CVE-2025-47650: WordPress Infility Global <= 2.15.09 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global allows Path Traversal. This issue affects Infility Global: from n/a through 2.14.7.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global infility-global allows Path Traversal.This issue affects Infility Global: from n/a through <= 2.15.11.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47650?
The severity of CVE-2025-47650 is classified as critical due to its potential for unauthorized access to file paths.
How do I fix CVE-2025-47650?
To fix CVE-2025-47650, update Infility Global to a version higher than 2.14.7 to ensure path traversal vulnerabilities are mitigated.
What versions are affected by CVE-2025-47650?
CVE-2025-47650 affects all versions of Infility Global from n/a up to and including 2.14.7.
Can CVE-2025-47650 be exploited remotely?
Yes, CVE-2025-47650 can be exploited remotely, allowing attackers to perform path traversal from outside the application.
What should I do if I cannot update the software for CVE-2025-47650?
If you cannot update the software for CVE-2025-47650, consider implementing access controls and web application firewalls to mitigate the risk.