PT-2025-1939 · WordPress · Infility Global Wordpress Plugin

Hassan Khan Yusufzai

+1

·

Published

2025-01-28

·

Updated

2025-05-24

·

CVE-2024-12723

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Infility Global WordPress plugin versions 2.9.8 and earlier
Description The issue arises because the Infility Global WordPress plugin does not properly sanitise and escape a parameter before outputting it back in the page. This leads to a Reflected Cross-Site Scripting issue, which could be used against high privilege users such as the administrator.
Recommendations Infility Global WordPress plugin version 2.9.8 and earlier: Update the Infility Global WordPress plugin to a version later than 2.9.8 to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-12723

Affected Products

Infility Global Wordpress Plugin