CVE-2026-8163 PUBLISHED

Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter

Assigner: WPScan
Reserved: 08.05.2026 Published: 23.06.2026 Updated: 23.06.2026

The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.

Product Status

Vendor Unknown
Product Infility Global
Versions Default: unaffected
  • affected from 0 to 2.15.19 (excl.)

Credits

  • TRAN THE LONG finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE