Arbitrary File Upload Vulnerability in Infility Global Plugin for WordPress
CVE-2025-12968
What is CVE-2025-12968?
The Infility Global plugin for WordPress has a significant vulnerability that allows authenticated users to upload arbitrary files due to insufficient file type validation and lack of capability checks. The issue arises from the upload_file function, which only verifies the MIME type and is susceptible to manipulation. Additionally, the import_data function does not enforce proper capability checks. This allows attackers with subscriber-level access or higher to exploit these weaknesses, potentially leading to remote code execution on the server hosting the affected site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Infility Global * <= 2.14.23
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved