CVE-2025-68865: WordPress Infility Global plugin <= 2.15.11 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global allows SQL Injection.This issue affects Infility Global: from n/a through 2.14.48.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global: from n/a through <= 2.15.11.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68865?
CVE-2025-68865 is classified as a high severity SQL Injection vulnerability affecting Infility Global.
How can I fix CVE-2025-68865?
To fix CVE-2025-68865, update Infility Global to a patched version beyond 2.14.48.
Which versions of Infility Global are affected by CVE-2025-68865?
CVE-2025-68865 affects Infility Global versions up to and including 2.14.48.
What exploit types are associated with CVE-2025-68865?
CVE-2025-68865 is associated with SQL injection attacks that can lead to unauthorized database access.
Is CVE-2025-68865 specific to any platforms?
CVE-2025-68865 is specific to the Infility Global plugin for WordPress.