{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/infility-global/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-10734"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Infility Global plugin for WordPress (2.15.21)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["Infility Global"],"content_html":"\u003cp\u003eThe Infility Global plugin for WordPress (versions 2.15.21 and earlier) contains a vulnerability due to insufficient input sanitization and output escaping. Specifically, the /cf7_record log endpoint allows unauthenticated attackers to inject malicious web scripts into the application's logging database. Because the /cf7_records viewer page is accessible to any authenticated user, including those with minimal Subscriber-level privileges, these injected scripts execute in the browser of any user who accesses the records interface. This flaw poses a significant risk to organizational WordPress instances by facilitating session hijacking, administrative account takeover, or the distribution of malicious redirects through legitimate site content.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an authenticated user's session. This can lead to the theft of session cookies, modification of site content, or the execution of unauthorized administrative actions, effectively compromising the WordPress site and the integrity of data handled within the admin interface.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Infility Global plugin for WordPress to version 2.15.22 or later to resolve CVE-2026-10734.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block requests to the /cf7_record endpoint containing script tags or common JavaScript event handlers (e.g., \u0026lt;script\u0026gt;, onerror, onload).\u003c/li\u003e\n\u003cli\u003eAudit logs for the /cf7_record endpoint to identify any suspicious HTTP POST requests containing payload strings that deviate from the expected logging schema.\u003c/li\u003e\n\u003cli\u003eApply the Sigma rule below to identify potential exploitation attempts in web server access logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T08:24:35Z","date_published":"2026-08-16T08:24:35Z","id":"https://feed.craftedsignal.io/briefs/2026-08-infility-xss/","summary":"The Infility Global WordPress plugin is vulnerable to Stored XSS via the /cf7_record endpoint, allowing unauthenticated attackers to execute arbitrary scripts in the context of authenticated users.","title":"Stored Cross-Site Scripting in Infility Global WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-infility-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Infility Global","version":"https://jsonfeed.org/version/1.1"}