SQL Injection Vulnerability in Infility Global Plugin for WordPress
CVE-2026-8685
6.5MEDIUM
What is CVE-2026-8685?
The Infility Global plugin for WordPress is susceptible to SQL Injection through the 'orderby' and 'order' parameters. This vulnerability arises due to inadequate escaping of user input and poor preparation in the SQL queries within the show_control_data::post_list() function. Authenticated attackers with Subscriber-level access or higher can exploit this flaw to inject malicious SQL queries, potentially enabling them to retrieve sensitive data from the database.
Affected Version(s)
Infility Global 0 <= 2.15.16