Boletines de Vulnerabilidades

CVE-2026-8163

   
Software afectado WORDPRESS
 
The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-8163