WordPress Plugin Vulnerabilities

Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter

Description

The Infility Global plugin for WordPress does not sanitize or validate the orderby and order parameters in the import_list(), url_detail(), and file_detail() admin page callbacks before using them in SQL queries, allowing authenticated attackers with Editor-level access or higher to perform time-based blind SQL injection and extract sensitive data from the database. The ImportData module must be enabled via the plugin's module toggle page.

Proof of Concept

Affects Plugins

Fixed in 2.15.20

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Mustafa Ahmed
Submitter
Mustafa Ahmed
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-06-02 (about 21 days ago)
Added
2026-06-02 (about 20 days ago)
Last Updated
2026-06-02 (about 20 days ago)

Other