
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15268 is an unauthenticated SQL injection vulnerability in the Infility Global plugin for WordPress, affecting all versions up to and including 2.14.46. The flaw exists in the infility_get_data API action, where insufficient input escaping and lack of prepared SQL statements allow attackers to inject malicious SQL queries without any authentication. It was published on February 4, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability stems from user-supplied parameters passed to the infility_get_data API action not being properly escaped or sanitized before being incorporated into SQL queries, enabling stacked or appended SQL injection under certain server configurations. Exploitation requires no authentication, no user interaction, and is remotely accessible over the network. Relevant vulnerable code paths have been identified in include/class/db.class.php (line 41), infility_global.php (line 626), and include/class/str.class.php (line 21) (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials, personal data, configuration details, and other confidential content. The confidentiality impact is rated High, while integrity and availability are unaffected by this specific vulnerability. Depending on the data exposed, attackers could leverage extracted credentials for account takeover or further lateral movement within the environment (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been confirmed at this time, though a Nuclei template pull request was submitted to ProjectDiscovery's nuclei-templates repository, indicating community interest in automated detection (Nuclei Templates PR). The EPSS score is approximately 0.071% (0.000710), reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
infility_get_data API action, which is exposed as an unauthenticated WordPress AJAX or REST API endpoint.; SELECT user_login, user_pass FROM wp_users-- -) to append additional queries to the existing SQL statement.mysqli multi-query support enabled), retrieve database contents such as WordPress user credentials, email addresses, or other sensitive records from the database.wp-admin/admin-ajax.php or REST API routes) with the action=infility_get_data parameter containing SQL metacharacters (e.g., ', ;, --, UNION, SELECT).admin-ajax.php with encoded or plaintext SQL syntax in query parameters from unexpected or foreign IP addresses; elevated database query error rates in WordPress debug logs.SELECT statements targeting wp_users or other sensitive tables.Users should update the Infility Global plugin to a version beyond 2.14.46 as soon as a patched release becomes available from the plugin vendor. In the interim, site administrators should consider deactivating or removing the plugin entirely to eliminate the attack surface. Additionally, deploying a Web Application Firewall (WAF) — such as Wordfence — can help detect and block SQL injection attempts targeting this endpoint (Wordfence, Wordfence Weekly Report).
Wordfence disclosed and reported this vulnerability as part of their weekly WordPress vulnerability intelligence report for February 2–8, 2026, highlighting it among notable plugin flaws (Wordfence Weekly Report). A Nuclei detection template was submitted to ProjectDiscovery's community repository, reflecting researcher interest in automated scanning for this flaw (Nuclei Templates PR). No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability aggregator postings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."