CVE-2025-12968 describes an arbitrary file upload vulnerability in the Infility Global WordPress plugin, affecting all versions up to and including 2.14.23. This critical flaw, stemming from inadequate file type validation and missing capability checks, allows authenticated attackers with subscriber-level access or higher to upload malicious files. With a CVSS score of 8.8 (HIGH), successful exploitation could lead to remote code execution, compromising the affected website. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.14.42CPE match | cpe:2.3:a:infility:infility_global:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.