Stored Cross-Site Scripting Vulnerability in Infility Global WordPress Plugin
CVE-2026-10734

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2026

What is CVE-2026-10734?

The Infility Global plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping mechanisms. The vulnerability is located in the /cf7_record Log Endpoint, which allows unauthenticated attackers to inject malicious web scripts that can be executed by any user accessing an infected page. This affects all plugin versions up to and including 2.15.21. Notably, the /cf7_records viewer is accessible to all authenticated users, including those with minimal Subscriber-level access, leading to potential exploitation through injected payloads.

Affected Version(s)

Infility Global 0 <= 2.15.21

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denny Abraham Sinaga (dennyabrahamsinaga)
.