CVE-2025-15268: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15268 is an unauthenticated SQL injection vulnerability in the Infility Global plugin for WordPress, affecting all versions up to and including 2.14.46. The flaw exists in the infility_get_data API action, where insufficient input escaping and lack of prepared SQL statements allow attackers to inject malicious SQL queries without any authentication. It was published on February 4, 2026, and assigned a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability stems from user-supplied parameters passed to the infility_get_data API action not being properly escaped or sanitized before being incorporated into SQL queries, enabling stacked or appended SQL injection under certain server configurations. Exploitation requires no authentication, no user interaction, and is remotely accessible over the network. Relevant vulnerable code paths have been identified in include/class/db.class.php (line 41), infility_global.php (line 626), and include/class/str.class.php (line 21) (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials, personal data, configuration details, and other confidential content. The confidentiality impact is rated High, while integrity and availability are unaffected by this specific vulnerability. Depending on the data exposed, attackers could leverage extracted credentials for account takeover or further lateral movement within the environment (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed at this time, though a Nuclei template pull request was submitted to ProjectDiscovery's nuclei-templates repository, indicating community interest in automated detection (Nuclei Templates PR). The EPSS score is approximately 0.071% (0.000710), reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Infility Global plugin (versions ≤ 2.14.46) using tools like WPScan, Shodan, or Google dorks targeting plugin-specific file paths.
  2. Locate the vulnerable endpoint: Target the infility_get_data API action, which is exposed as an unauthenticated WordPress AJAX or REST API endpoint.
  3. Craft malicious SQL payload: Inject unsanitized SQL into the vulnerable user-supplied parameter (e.g., appending ; SELECT user_login, user_pass FROM wp_users-- -) to append additional queries to the existing SQL statement.
  4. Extract sensitive data: Depending on server configuration (e.g., mysqli multi-query support enabled), retrieve database contents such as WordPress user credentials, email addresses, or other sensitive records from the database.
  5. Post-exploitation: Use extracted admin credentials to log into the WordPress dashboard and achieve full site compromise, or use harvested data for further attacks (Wordfence, Infinitsec).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to WordPress AJAX endpoints (e.g., wp-admin/admin-ajax.php or REST API routes) with the action=infility_get_data parameter containing SQL metacharacters (e.g., ', ;, --, UNION, SELECT).
  • Logs: Web server access logs showing requests to admin-ajax.php with encoded or plaintext SQL syntax in query parameters from unexpected or foreign IP addresses; elevated database query error rates in WordPress debug logs.
  • Database: Unexpected or anomalous query patterns in MySQL/MariaDB general query logs, particularly stacked queries or SELECT statements targeting wp_users or other sensitive tables.
  • File System: Presence of new or modified PHP files in the WordPress installation (potential webshells) if the attacker escalated beyond data extraction.

Mitigation and workarounds

Users should update the Infility Global plugin to a version beyond 2.14.46 as soon as a patched release becomes available from the plugin vendor. In the interim, site administrators should consider deactivating or removing the plugin entirely to eliminate the attack surface. Additionally, deploying a Web Application Firewall (WAF) — such as Wordfence — can help detect and block SQL injection attempts targeting this endpoint (Wordfence, Wordfence Weekly Report).

Community reactions

Wordfence disclosed and reported this vulnerability as part of their weekly WordPress vulnerability intelligence report for February 2–8, 2026, highlighting it among notable plugin flaws (Wordfence Weekly Report). A Nuclei detection template was submitted to ProjectDiscovery's community repository, reflecting researcher interest in automated scanning for this flaw (Nuclei Templates PR). No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability aggregator postings.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management