CVE-2026-8163: Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter
Published Jun 23, 2026
·Updated
The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.
Affected Software
1 affected component
Infility Infility Global (WordPress plugin)<2.15.19
Event History
Jun 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-8163?
CVE-2026-8163 has a severity rating of 8.8, classified as high.
2
How does CVE-2026-8163 affect my site?
CVE-2026-8163 allows authenticated users with Subscriber-level access and above to exploit a SQL Injection vulnerability.
3
How do I fix CVE-2026-8163?
To fix CVE-2026-8163, update the Infility Global WordPress plugin to version 2.15.19 or later.
4
Who is vulnerable to CVE-2026-8163?
Any systems using Infility Global plugin versions before 2.15.19 are vulnerable to CVE-2026-8163.
5
What type of vulnerability is CVE-2026-8163?
CVE-2026-8163 is classified as an SQL Injection vulnerability.