CVE-2025-47651: WordPress Infility Global plugin <= 2.15.11 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global allows SQL Injection. This issue affects Infility Global: from n/a through 2.12.4.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global: from n/a through <= 2.15.11.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47651?
CVE-2025-47651 has been classified as a high severity vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
How do I fix CVE-2025-47651?
To fix CVE-2025-47651, upgrade your Infility Global software to version 2.12.5 or later to ensure the vulnerability is patched.
What versions of Infility Global are affected by CVE-2025-47651?
CVE-2025-47651 affects Infility Global from version n/a up to and including version 2.12.4.
Can CVE-2025-47651 be exploited remotely?
Yes, CVE-2025-47651 can be exploited remotely, allowing attackers to execute malicious SQL queries against vulnerable installations.
What are the potential impacts of exploiting CVE-2025-47651?
Exploiting CVE-2025-47651 can lead to data theft, unauthorized database manipulation, and potentially full system takeover.