Junglewise Threat Intelligence

CVE-2026-8163: Infility Global WordPress plugin SQL injection in order parameter

CVE-2026-8163 · Severity: info · CVSS 7.7 · Published 2026-06-23

Technologies: Infility Global. Vendors: Infility Global.

Executive brief

The Infility Global plugin for WordPress is vulnerable to a security flaw that allows logged-in users, even those with low-level 'Subscriber' permissions, to interfere with the website's database. By sending specially crafted requests, an attacker can extract sensitive information, modify data, or cause service disruptions. This could lead to the theft of customer information or full site compromise.

Technical details

A SQL injection vulnerability exists in the Infility Global WordPress plugin due to insufficient sanitization and escaping of the 'order' and 'orderby' parameters within the 'control-data' admin page. The plugin appends these parameters directly to SQL queries executed via $wpdb->get_results() without using prepared statements. An authenticated attacker with at least Subscriber-level privileges can exploit this via a crafted GET request to /wp-admin/admin.php. This can be used to perform time-based blind SQL injection or UNION-based attacks to exfiltrate arbitrary data from the WordPress database. The issue is fixed in version 2.15.19.

Affected products

  • Infility Global Infility Global < 2.15.19

Timeline

  • 2026-06-02: disclosed: Initial public disclosure by WPScan
  • 2026-06-23: advisory: NVD publication date
  • 2026-06-23: patched: Fix released in version 2.15.19

References

Related threats