VYPR

Ajax Load More

by WordPress

Source repositories

CVEs (10)

  • CVE-2015-10140HigJul 22, 2025
    risk 0.60cvss 8.8epss 0.01

    The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

  • CVE-2021-24140HigMar 18, 2021
    risk 0.47cvss 7.2epss 0.01

    Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.

  • CVE-2026-6495HigMay 18, 2026
    risk 0.46cvss 7.1epss 0.00

    The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

  • CVE-2025-4775MedJun 17, 2025
    risk 0.42cvss 6.4epss 0.00

    The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2025-5586MedJun 6, 2025
    risk 0.42cvss 6.4epss 0.00

    The WordPress Ajax Load More and Infinite Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2025-47630MedMay 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More ajax-load-more allows Stored XSS.This issue affects Ajax Load More: from n/a through <= 7.3.1.2.

  • CVE-2025-59582MedSep 22, 2025
    risk 0.35cvss 5.3epss 0.01

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More ajax-load-more allows Retrieve Embedded Sensitive Data.This issue affects Ajax Load More: from n/a through <= 7.6.0.2.

  • CVE-2025-15525MedJan 31, 2026
    risk 0.34cvss 5.3epss 0.00

    The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for…

  • CVE-2024-1790MedApr 9, 2024
    risk 0.25cvss 4.9epss 0.01

    The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the…

  • CVE-2026-15360CriAug 5, 2026
    risk 0.00cvss 9.1epss 0.00

    The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.