CVE-2025-68864: WordPress Infility Global plugin <= 2.15.11 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Stored XSS.This issue affects Infility Global: from n/a through <= 2.15.11.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Infility Infility Global infility-global allows Stored XSS.This issue affects Infility Global: from n/a through <= 2.15.12.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68864?
CVE-2025-68864 has a high severity due to its potential for stored cross-site scripting (XSS) attacks in the Infility Global plugin.
How do I fix CVE-2025-68864?
To fix CVE-2025-68864, update the Infility Global plugin to the latest version beyond 2.14.50.
What types of attacks can be executed due to CVE-2025-68864?
CVE-2025-68864 can lead to stored XSS attacks, allowing attackers to inject malicious scripts into web pages.
Which versions of Infility Global are affected by CVE-2025-68864?
CVE-2025-68864 affects all versions of Infility Global plugin up to and including 2.14.50.
Is there a workaround for CVE-2025-68864 if I cannot update immediately?
There is no confirmed workaround for CVE-2025-68864, so updating the plugin is the recommended course of action.