CVE-2025-47652: WordPress Infility Global plugin <= 2.13.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global allows Reflected XSS. This issue affects Infility Global: from n/a through 2.13.4.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Reflected XSS.This issue affects Infility Global: from n/a through <= 2.13.4.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47652?
CVE-2025-47652 has a high severity rating due to its potential to allow attackers to execute malicious scripts in users' browsers.
How can I protect my application from CVE-2025-47652?
To protect against CVE-2025-47652, ensure that your Infility Global software is updated to version 2.13.5 or later, where the vulnerability is addressed.
What type of vulnerability is CVE-2025-47652?
CVE-2025-47652 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
Which versions of Infility Global are affected by CVE-2025-47652?
CVE-2025-47652 affects all versions of Infility Global up to and including 2.13.4.
What can happen if CVE-2025-47652 is exploited?
If exploited, CVE-2025-47652 can lead to unauthorized actions being performed on behalf of users or the theft of sensitive information.