Junglewise Threat Intelligence

CVE-2026-8685: Infility Global WordPress plugin SQL injection in post_list

CVE-2026-8685 · Severity: medium · CVSS 6.5 · Published 2026-05-20

Technologies: Infility Global. Vendors: Infility Global.

Executive brief

The Infility Global plugin for WordPress, which provides data display and control widgets, contains a security flaw that allows users with low-level account access to perform unauthorized database queries. By exploiting this vulnerability, an attacker could extract sensitive information from the website's database, potentially compromising user data or site configuration. This issue affects all versions of the plugin up to and including 2.15.16.

Technical details

The Infility Global plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping of user-supplied parameters and a lack of SQL query preparation within the show_control_data::post_list() function. The vulnerability specifically affects the 'orderby' and 'order' parameters. This function is registered as an admin menu page requiring only 'read' capabilities, allowing authenticated attackers with Subscriber-level access or higher to inject malicious SQL commands. An attacker can leverage this to append additional queries to existing database calls and extract sensitive information. The issue is present in all versions up to and including 2.15.16.

Affected products

  • Infility Global Infility Global up to, and including, 2.15.16

Timeline

  • 2026-05-20: advisory: NVD publication date

References

Related threats