Arbitrary File Upload Vulnerability in Infility Global Plugin for WordPress
CVE-2025-12968
8.8HIGH
What is CVE-2025-12968?
The Infility Global plugin for WordPress has a significant vulnerability that allows authenticated users to upload arbitrary files due to insufficient file type validation and lack of capability checks. The issue arises from the upload_file function, which only verifies the MIME type and is susceptible to manipulation. Additionally, the import_data function does not enforce proper capability checks. This allows attackers with subscriber-level access or higher to exploit these weaknesses, potentially leading to remote code execution on the server hosting the affected site.
Affected Version(s)
Infility Global 0 <= 2.14.42