CVE-2026-7842
Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orderby and order parameters in the import_list(), url_detail(), and file_detail() admin page callbacks before using them in SQL queries, allowing authenticated attackers with Editor-level access or higher to perform time-based blind SQL injection and extract sensitive data from the database. The ImportData module must be enabled via the Infility Global WordPress plugin before 2.15.20's module toggle page.
| Vendor | unknown |
| Product | infility global |
| Published | Jun 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown infility global
Be the first to know when new unknown vulnerabilities affecting unknown infility global are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Infility Global
0 < 2.15.20
References
Credits
Mustafa Ahmed WPScan