Stored Cross-Site Scripting Vulnerability in Infility Global WordPress Plugin
CVE-2026-10734
7.2HIGH
What is CVE-2026-10734?
The Infility Global plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping mechanisms. The vulnerability is located in the /cf7_record Log Endpoint, which allows unauthenticated attackers to inject malicious web scripts that can be executed by any user accessing an infected page. This affects all plugin versions up to and including 2.15.21. Notably, the /cf7_records viewer is accessible to all authenticated users, including those with minimal Subscriber-level access, leading to potential exploitation through injected payloads.
Affected Version(s)
Infility Global 0 <= 2.15.21