{"error":0,"message":null,"data":{"name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load","plugin":"ajax-load-more","link":"https:\/\/wordpress.org\/plugins\/ajax-load-more\/","latest":"1784742000","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"96801cc288fa1338cda66d360349bc1a2841d8c6ab9c55a205155ca3dded80af","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24140","name":"CVE-2021-24140","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24140","description":"[en] Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST \/wp-admin\/admin-ajax.php with param repeater=' or sleep(5)#&type=test.","date":"2021-03-18"},{"id":"1876312e-3dba-4909-97a5-afbb76fbc056","name":"Ajax Load More &lt; 5.3.2 - Authenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/1876312e-3dba-4909-97a5-afbb76fbc056","description":"The Ajax Load More WordPress plugin was vulnerable to SQL Injection in POST \/wp-admin\/admin-ajax.php with param repeater=&#039; or sleep(5)#&amp;type=test.\r\n\r\nThe attacker needs to be authenticated with the edit_theme_options capability, which only administrators have by default.","date":null},{"id":"4b85c70702b9750884f2bfb0dcd65505035a3e4a","name":"Ajax Load More plugin < 5.3.2 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-plugin-532-sql-injection","description":"Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST \/wp-admin\/admin-ajax.php with param repeater=' or sleep(5)#&type=test.","date":"2020-05-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"9573447bab398c9c3979c9ab7a43c7cb7a61f1bdd43b86c1a84fe460eb47567c","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bffd58ad20a3efe0623a5d2cc20e0447f123abe4","name":"WordPress Ajax Load More plugin <= 5.3.1 - Authenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-5-3-1-authenticated-sql-injection-sqli-vulnerability","description":"Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Khanh in WordPress Ajax Load More plugin (versions <= 5.3.1).","date":"2020-05-18"}],"impact":[]},{"uuid":"657e5f7fc88c7391f93ddee7b0b27fded0ba25b5b453452aace1868bec8a1777","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6101be7b179db7436746765bfc143a8dcbc90262","name":"WordPress Ajax Load More Plugin <= 2.11.1 - Local File Inclusion","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-2-11-1-local-file-inclusion","description":"Because of this vulnerability, attackers can run arbitrary PHP code.\nUpgrade the plugin.","date":"2016-08-15"}],"impact":[]},{"uuid":"8f7b2bfa30b65660303b53b89484b9f5fb1cb765f77b139770bd156a9aa22229","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5cd592f6d79de8bb83d447adf0539500f5339290","name":"WordPress Ajax Load More Plugin 2.8.1.1 - PHP Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-2-8-1-1-php-upload","description":"Ajax Load More plugin is prone to a PHP upload vulnerability that allows to get remote code execution.\nUpgrade the plugin.","date":"2015-11-09"}],"impact":[]},{"uuid":"a48cb849956266ca459e8c2898bc07bfb982224cd9ce13c540327469b0ae363f","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1386c96159832db6140bf003d5562d3777b40e1a","name":"WordPress Ajax Load More Plugin < 2.8.2 - File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-2-8-2-file-upload","description":"This vulnerability allows an attacker to upload arbitrary files to the affected computer.\nUpgrade the plugin.","date":"2015-10-18"}],"impact":[]},{"uuid":"f2a1085c2567451ff438e01d7ec75a54f03587a44a7e0dedf17d400d6ccd3381","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2433","name":"CVE-2022-2433","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2433","description":"[en] The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.","date":"2022-09-06"},{"id":"b0be77cb712cad3258d6bf561eb0fcbe6745324b","name":"WordPress Ajax Load More plugin <= 5.5.3 - PHAR Deserialization via Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-5-5-3-phar-deserialization-via-cross-site-request-forgery-csrf-vulnerability","description":"PHAR Deserialization via Cross-Site Request Forgery (CSRF) vulnerability discovered by Rasoul Jahanshahi in WordPress Ajax Load More plugin (versions <= 5.5.3).\nUpdate the WordPress Ajax Load More plugin to the latest available version (at least 5.5.4).","date":"2022-08-22"},{"id":"bcd7e22ebd9854235b4c82636b47043b68f922b8","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 5.5.3 - Cross-Site Request Forgery to PHAR Deserialization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-553-cross-site-request-forgery-to-phar-deserialization","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site administrator into performing an action such as clicking on a link, that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.","date":"2022-08-22"},{"id":"d33b4230-81f2-436f-a1e5-2c9984cded19","name":"Ajax Load More &lt; 5.5.4 - PHAR Deserialization via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/d33b4230-81f2-436f-a1e5-2c9984cded19","description":"The plugin does not validate user input before using it to generate a path, allowing attacker to fully control it and use any wrapper, such as PHAR which could lead to deserialisation if they can trick an admin to open a malicious link and a suitable gadget chain is present","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"7.5","severity":"h","exploitable":"1.6","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"7.5","severity":"high","av":"network","ac":"high","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.6","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"9cd4229d5c7f9e694d6be786bfd92b190ddf812a322c94f4a0b9905046e66396","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2943","name":"CVE-2022-2943","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2943","description":"[en] The WordPress Infinite Scroll \u2013 Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to download arbitrary files hosted on the server that may contain sensitive content, such as the wp-config.php file.","date":"2022-09-06"},{"id":"12fa810de7b1003e78e162013a3f7f3a4ed4f388","name":"WordPress Ajax Load More plugin <= 5.5.3 - Authenticated Arbitrary File Read vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-5-5-3-authenticated-arbitrary-file-read-vulnerability","description":"Authenticated Arbitrary File Read vulnerability discovered by Muhammad Zeeshan (Xib3rR4dAr) in WordPress Ajax Load More plugin (versions <= 5.5.3).\nUpdate the WordPress Ajax Load More plugin to the latest available version (at least 5.5.4).","date":"2022-08-22"},{"id":"36c5dc42afffadab320d3c9648d78bedef3e83ae","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 5.5.3 - Authenticated (Admin+) Arbitrary File Read","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-553-authenticated-admin-arbitrary-file-read","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to download arbitrary files hosted on the server that may contain sensitive content, such as the wp-config.php file.","date":"2022-08-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"1.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"1.2","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"60489afc59b606e8e64deaf0591e080c0b6000946e4ba171c606bb5ec13a08e4","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2945","name":"CVE-2022-2945","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2945","description":"[en] The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2022-09-06"},{"id":"697654149c0b4dcf07aa04f08aec694e6c6ec270","name":"WordPress Ajax Load More plugin <= 5.5.3 - Directory Traversal vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-5-5-3-authenticated-arbitrary-file-read-vulnerability-2","description":"Directory Traversal vulnerability discovered by Muhammad Zeeshan (Xib3rR4dAr) in WordPress Ajax Load More plugin (versions <= 5.5.3).\nUpdate the WordPress Ajax Load More plugin to the latest available version (at least 5.5.4).","date":"2022-08-22"},{"id":"299d5311a5173f95cc63f9b2ccd30b4cf649f5e2","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 5.5.3 - Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-553-directory-traversal","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2022-08-22"},{"id":"f45b251d-1045-463b-9f74-9a010e8775b6","name":"Ajax Load More &lt; 5.5.4 - Admin+ Arbitrary File Read","link":"https:\/\/wpscan.com\/vulnerability\/f45b251d-1045-463b-9f74-9a010e8775b6","description":"The plugin does not validate a path which could allow high privilege users such as admin to read arbitrary files from the server","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"2.7","severity":"l","exploitable":"1.2","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"2.7","severity":"low","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"1.2","impact":"1.4"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"a41af647b4751e18590a1a2d3a744146e62a3d9b9a619da5853aaee6bc31452d","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"82650c97-3752-441a-9365-417ef148285d","name":"Ajax Load More &lt;= 2.11.1 - Local File Inclusion (LFI)","link":"https:\/\/wpscan.com\/vulnerability\/82650c97-3752-441a-9365-417ef148285d","description":"NOTE: The victim should have the paid add-on Custom Repeater or Unlimited installed.","date":null}],"impact":[]},{"uuid":"71d8a87683485c11c444910c62fccbb6bb42f792cd28e86a643fde3a12a3079b","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9f0c926e-0609-4c89-a724-88e16bcfa82a","name":"Ajax Load More &lt;= 2.8.1.1 - Authenticated File Upload &amp; Deletion","link":"https:\/\/wpscan.com\/vulnerability\/9f0c926e-0609-4c89-a724-88e16bcfa82a","description":"Authenticated file upload in file ajax-load-more\/admin\/admin.php file, in the function alm_save_repeater().\r\n\r\nThe variable $f is set to a predictable PHP file path, and then the content of the variable $c is written into that file.\r\n\r\nThe following code proves that this second variable is also set from untrusted input :\r\n$c = Trim(stripslashes($_POST[&quot;value&quot;])); \/\/ Repeater Value\r\n\r\nTherefore, an evil person can write arbitrary PHP code to the website by doing a POST query to http:\/\/&lt;WP-path&gt;\/wp-admin\/admin-ajax.php\r\n\r\nHe can then execute the evil PHP code for example by sending a simple request to http:\/\/&lt;WP-path&gt;\/wp-content\/plugins\/ajax-load-more\/core\/repeater\/default.php\r\n\r\nAuthenticated file deletion in file ajax-load-more\/admin\/admin.php file, in the function alm_delete_cache().\r\n\r\n$cache = $_POST[&quot;cache&quot;];\r\n[...]\r\n$dir = ALM_CACHE_PATH .&#039;_cache\/&#039;.$cache;\r\n[...]\r\nforeach (glob($dir.&quot;\/*.*&quot;) as $filename) {\r\n[...]\r\nunlink($filename);\r\n[...]\r\nrmdir($dir);","date":null}],"impact":[]},{"uuid":"2a5a0e959227e0e2bc6e33688850074fc2e52d064abbb1524ed6a83a7d5bea05","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6fee53d2a7f3840d6c22989df6a9bde28d724e4a","name":"Infinite Scroll \u2013 Ajax Load More <= 5.5.4 - Authenticated (Admin+) Arbitrary File Read via Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/infinite-scroll-ajax-load-more-554-authenticated-admin-arbitrary-file-read-via-directory-traversal","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4. This makes it possible administrative users to download sensitive files from the server, in addition to unauthenticated users triggering administrators to retrieve sensitive files from the server due to missing nonce protection on the function.","date":"2022-08-31"}],"impact":[]},{"uuid":"c0c6059424b304a3a33bbe818904dac49808dc03ca5114088d0d721b47c33608","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1f1a88a5d1b72cafaf168ffc8bd23861727b07c8","name":"Ajax Load More < 2.11.2 - Local File Inclusion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-2112-local-file-inclusion","description":"The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeater' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other \u201csafe\u201d file types can be uploaded and included.","date":"2016-08-15"}],"impact":[]},{"uuid":"88a6a5c320322a833b609ea351bd3aea0289f9767ad18cabb4cd274abee992be","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4ad2f864343690ceb1ed98c31bdebb6c670bd1e5","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 2.8.1.1 - Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-2811-arbitrary-file-upload","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'alm_save_repeater()' function called via an AJAX action in versions up to, and including, 2.8.1.2. This makes it possible for authenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.","date":"2015-10-10"},{"id":"CVE-2015-10140","name":"CVE-2015-10140","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-10140","description":"[en] The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.","date":"2025-07-22"},{"id":"EUVD-2015-9400","name":"EUVD-2015-9400","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2015-9400","description":"The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.","date":"2025-07-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"6a179886364f12df93042f717c1f654fd79986a9c5a285567668b3e1d1616392","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.6.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.6.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-4466","name":"CVE-2022-4466","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4466","description":"[en] The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.","date":"2023-03-13"},{"id":"66a3104a11fab6440553c167ab168409f9a7694a","name":"WordPress Infinite Scroll - Ajax Load More <= 5.6.0.2 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-5602-authenticated-contributor-stored-cross-site-scripting","description":"The WordPress Infinite Scroll - Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.6.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-02-27"},{"id":"89d6d484e76f28d2d003edf1483097989db380dd","name":"WordPress  Ajax Load More Plugin  < 5.6.0.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-5-6-0-3-contributor-stored-xss-vulnerability","description":"Update the WordPress Ajax Load More plugin to the latest available version (at least 5.6.0.3).\nLana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ajax Load More Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 5.6.0.3.","date":"2023-03-14"},{"id":"497d0bf9-b750-4293-9662-1722a74442e2","name":"WordPress Infinite Scroll - Ajax Load More &lt; 5.6.0.3 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/497d0bf9-b750-4293-9662-1722a74442e2","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0473542067720a77e861000414e3240813f01f873d458c842dae7266fc183d33","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3207bbea-b4dc-4ae0-8a48-d7089ba7107f","name":"Ajax Load More &lt; 5.5.4.1 - Admin+ Arbitrary File Read","link":"https:\/\/wpscan.com\/vulnerability\/3207bbea-b4dc-4ae0-8a48-d7089ba7107f","description":"The plugin does not properly validates paths generated with user input in the alm_repeaters_export() function, which could allow high privilege users to read arbitrary files form the server (even when they should not be able to have access to any, for example in multisite setup)\r\n\r\nThis is due to an incomplete fix of CVE-2022-2943","date":null}],"impact":[]},{"uuid":"2880e842523d0d596914829799ccf9402c7819f35786a2f89de7bb29bc4eaa89","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 6.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-50874","name":"CVE-2023-50874","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-50874","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney WordPress Infinite Scroll \u2013 Ajax Load More allows Stored XSS.This issue affects WordPress Infinite Scroll \u2013 Ajax Load More: from n\/a through 6.1.0.1.","date":"2023-12-28"},{"id":"276902213c0ed38ef0cf6815c83b69b1a0d241cb","name":"WordPress  Ajax Load More Plugin  <= 6.1.0.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-6-1-0-1-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Ajax Load More plugin to the latest available version (at least 6.2.0).\nNg\u00f4 Thi\u00ean An (ancorn_ from VNPT-VCI) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ajax Load More Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.2.0.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-22"},{"id":"9b5ac44eaed11f4189f55e7108576a2b9f5e794e","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 6.1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-6101-authenticated-contributor-stored-cross-site-scripting","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to 6.1.0.1 (inclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-22"},{"id":"0a1f98c3-7645-4bb9-9b40-0c5766ed36cd","name":"WordPress Infinite Scroll - Ajax Load More &lt; 6.2 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/0a1f98c3-7645-4bb9-9b40-0c5766ed36cd","description":"The plugin does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"c7ca65564a04586ed2741f5347d905fe8e52e81000fb98905937c55934404723","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1790","name":"CVE-2024-1790","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1790","description":"[en] The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This is limited to Windows instances.","date":"2024-04-09"},{"id":"93119a88660ac800034872472b24626416047438","name":"Ajax Load More <= 7.0.1 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-701-authenticated-admin-directory-traversal-to-arbitrary-file-read","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This is limited to Windows instances.","date":"2024-03-26"},{"id":"805da9f0093aefcdd5149e32ad68243739c97c1b","name":"WordPress  Ajax Load More Plugin    <= 7.0.1 is vulnerable to Directory Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-7-0-1-auth-directory-traversal-to-arbitrary-file-read-vulnerability","description":"Update the WordPress Ajax Load More plugin to the latest available version (at least 7.1.0).\nHoa Le Ngoc (lengochoa) discovered and reported this Directory Traversal vulnerability in WordPress Ajax Load More Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files\/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 7.1.0.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"8f269342-96a6-4f42-bdc5-a81d8707e7f3","name":"Ajax Load More &lt; 7.1.0 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read","link":"https:\/\/wpscan.com\/vulnerability\/8f269342-96a6-4f42-bdc5-a81d8707e7f3","description":"The WordPress Infinite Scroll &ndash; Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the &#039;type&#039; parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This is limited to Windows instances.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"1.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"1.2","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b34a745e2a42bdd879bbf4b6fcbbaf5ca26589319246c61da84bd5d9152d6af2","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d097822c48991bc8eeff385dff4b998eb2263e61","name":"Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-701-authenticated-administrator-stored-cross-site-scripting","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-03-28"},{"id":"CVE-2026-15295","name":"CVE-2026-15295","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15295","description":"[en] The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-07-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"h","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"4.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"4.4","severity":"medium","av":"network","ac":"high","pr":"high","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-692","name":"Incomplete Denylist to Cross-Site Scripting","description":"The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2dd3665140cad03acfb15787b6418c4bd3c76bc33b31fe22aefe57a38463a93b","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"32f330dab393f263d52f4070533ebb5d8fd53914","name":"WordPress  Ajax Load More Plugin    <= 7.0.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-7-0-1-authenticated-administrator-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Ajax Load More plugin to the latest available version (at least 7.0.2).\nafei discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ajax Load More Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 7.0.2.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":[]},{"uuid":"80a36bb7059cf21497c1da2a7a26150649dd81a4b81791c36cfdbfa0d8d4f07e","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4711","name":"CVE-2024-4711","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4711","description":"[en] The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-01"},{"id":"395580ddd9ba15929eced8e16fcb85bdf29ef0ba","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-711-authenticated-contributor-cross-site-scripting","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-31"},{"id":"c12b2fa3660cca94beb9f6beb13e1442648282db","name":"WordPress Ajax Load More Plugin <= 7.1.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-7-1-1-authenticated-contributor-cross-site-scripting-vulnerability","description":"<p>WordPress Ajax Load More Plugin <= 7.1.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ajax Load More<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ajax-load-more\/#developers<\/p><p>Affected Version <= 7.1.1<\/p><p>Fixed in version 7.1.2 <\/p>","date":"2024-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"13ab9016d16ed43a8e1725a88557f560123d2060a08d46397a7f662b0703ac3f","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-8505","name":"CVE-2024-8505","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-8505","description":"[en] The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018button_label\u2019 parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-10-02"},{"id":"137508ae32ef39a2696d8d7dc785cce397a0f74b","name":"WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-712-authenticated-contributor-stored-cross-site-scripting-via-button-label-parameter","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018button_label\u2019 parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-10-01"},{"id":"d46f6b89c9fe60a975531d854ee2b0122f0f2e1a","name":"WordPress Ajax Load More Plugin <= 7.1.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-plugin-7-1-2-authenticated-contributor-stored-cross-site-scripting-via-button-label-parameter-vulnerability","description":"<p>WordPress Ajax Load More Plugin <= 7.1.2 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ajax Load More<\/p><p>Link: https:\/\/wordpress.org\/plugins\/ajax-load-more\/#developers<\/p><p>Affected Version <= 7.1.2<\/p><p>Fixed in version 7.1.3 <\/p>","date":"2024-10-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-87","name":"Improper Neutralization of Alternate XSS Syntax","description":"The product does not neutralize or incorrectly neutralizes user-controlled input for alternate script syntax."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"41bb5975d5f22963b5abdfaf4f83e0a808daeacf62ba0da403757a3d902914e7","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.3.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.3.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-47630","name":"CVE-2025-47630","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-47630","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n\/a through 7.3.1.","date":"2025-05-07"},{"id":"EUVD-2025-13754","name":"EUVD-2025-13754","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-13754","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n\/a through 7.3.1.","date":"2025-05-07"},{"id":"d7d754f105949c5a20d5a9c1d4c2ae0350de3d70","name":"WordPress Ajax Load More Plugin <= 7.3.1.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/ajax-load-more\/vulnerability\/wordpress-ajax-load-more-7-3-1-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Ajax Load More Plugin <= 7.3.1.2 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Ajax Load More<\/p><p>Affected Version <= 7.3.1.2<\/p><p>CVE: CVE-2025-47630<\/p>","date":"2025-05-07"},{"id":"a4b8298d3e39821239b056cc2ccca56aec99cc80","name":"Ajax Load More <= 7.3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-7312-authenticated-contributor-stored-cross-site-scripting","description":"The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"7275b4a3208299ddd2d928cee69bfb861f927745591944f0c4b26a5d219cbe60","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4775","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4775","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"4983b70eccbd987c00a209810f704f8c71006e10","name":"WordPress Infinite Scroll \u2013 Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/wordpress-infinite-scroll-ajax-load-more-7401-authenticatedcontributor-stored-cross-site-scripting","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-16"},{"id":"EUVD-2025-18448","name":"EUVD-2025-18448","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-18448","description":"The WordPress Infinite Scroll \u2013 Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3a7dbceac8b6416ecaafccf8d8f970dbddf0ff7002a4e7cee622f77976b16939","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-15525","name":"CVE-2025-15525","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-15525","description":"[en] The Ajax Load More \u2013 Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles and excerpts of private, draft, pending, scheduled, and trashed posts.","date":"2026-01-31"},{"id":"EUVD-2025-206596","name":"EUVD-2025-206596","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-206596","description":"The Ajax Load More \u2013 Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles and excerpts of private, draft, pending, scheduled, and trashed posts.","date":"2026-01-31"},{"id":"7ab4e4123122614873b383b3e993fb42dabb9aa3","name":"Ajax Load More \u2013 Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private\/Draft Post Title and Excerpt Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-infinite-scroll-lazy-load-load-more-781-incorrect-authorization-to-unauthenticated-privatedraft-post-title-and-excerpt-exposure","description":"The Ajax Load More \u2013 Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles and excerpts of private, draft, pending, scheduled, and trashed posts.","date":"2026-01-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6ccdf58a4da645fbf1cbdb4c713b56017532d0c3ee0e2fdcaf7c157d5c291b8e","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-59582","name":"WordPress Ajax Load More Plugin <= 7.6.0.2 - Sensitive Data Exposure Vulnerability","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-59582","description":"Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More ajax-load-more allows Retrieve Embedded Sensitive Data.This issue affects Ajax Load More: from n\/a through <= 7.6.0.2.","date":"0000-00-00"},{"id":"0fc36bb4403d5b8190e22f4e65a102de06fe94f7","name":"Ajax Load More <= 7.6.0.2 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-7602-unauthenticated-sensitive-information-exposure","description":"The Ajax Load More \u2013 Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2025-09-22"},{"id":"EUVD-2025-30467","name":"EUVD-2025-30467","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-30467","description":"Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More allows Retrieve Embedded Sensitive Data. This issue affects Ajax Load More: from n\/a through 7.6.0.2.","date":"2025-09-22"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":null,"impact":null}}},{"uuid":"3d5e58e2dd5d05848ccbd6960682655395529bef1fc0637091a09158dca8d3ff","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6495","name":"CVE-2026-6495","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6495","description":"[en] The Ajax Load More  WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":"2026-05-18"},{"id":"3304ac5246052ffef93e6f0539a928d3f7486788","name":"Ajax Load More \u2013 Infinite Scroll, Load More, & Lazy Load < 7.8.4 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/1baa699e-b071-490c-b932-2dea603165e1","description":"The Ajax Load More \u2013 Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-11"},{"id":"fee2455fdf75f136fa1d1cf0efbd12f60f3a97fa","name":"Ajax Load More \u2013 Infinite Scroll, Load More, & Lazy Load < 7.8.4 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-infinite-scroll-load-more-lazy-load-784-unauthenticated-stored-cross-site-scripting","description":"The Ajax Load More \u2013 Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-01-30"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6d68f7aabbbf7efaea3639615e00912f5f8ef083192d23cdd2d30944be4bbc69","name":"Ajax Load More \u2013 Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 8.0.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.0.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15360","name":"CVE-2026-15360","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15360","description":"[en] The Ajax Load More  WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.","date":"2026-08-05"},{"id":"22b65d58c5b8cfae3150219237348aa76225aee0","name":"Ajax Load More <= 8.0.0 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/ajax-load-more\/ajax-load-more-800-unauthenticated-sql-injection","description":"The Ajax Load More plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-07-29"}],"impact":{"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1786948043"}