High 7.5 Unfixed
2026-02-04≤ 2.14.46
Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass
Minimum safe version
2.14.43
Update to 2.14.43 or later to address 5 fixable vulnerabilities
Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass
CVE-2025-68864
WordPress Infility Global plugin <= 2.15.06 - SQL Injection vulnerability
CVE-2025-12968
WordPress Infility Global <= 2.15.06 - Arbitrary File Download vulnerability
CVE-2025-47652
WordPress Infility Global plugin <= 2.15.06 - Cross Site Scripting (XSS) vulnerability
WordPress Infility Global plugin <= 2.15.06 - SQL Injection vulnerability
CVE-2024-12723
CVE-2024-11496
CVE-2024-12290