plugin

Ajax Load More Vulnerabilities

44 known security issues reported for the Ajax Load More WordPress plugin. Most recent disclosed Jul 29, 2026.

1 critical 5 high 13 medium

Running Ajax Load More on your site? Check whether your installed version is affected.

Scan your site free

Ajax Load More <= 8.0.0 - Unauthenticated SQL Injection

high

The Ajax Load More plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries i...

CVSS:
7.5
Affected:
up to 8.0.0
Fixed in:
8.0.1
Disclosed:
Jul 29, 2026

CVE-2026-15360 on NVD →

Ajax Load More – Infinite Scroll, Load More, & Lazy Load < 7.8.4 - Unauthenticated Stored Cross-Site Scripting

high

The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu...

CVSS:
7.2
Affected:
up to 7.8.4
Fixed in:
7.8.4
Disclosed:
Jun 11, 2026

CVE-2026-6495 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.8.2

unknown

[en] The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles an...

Affected:
up to 7.8.2
Fixed in:
7.8.2
Disclosed:
Jan 31, 2026

CVE-2025-15525 on NVD →

Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure

medium

The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles and exc...

CVSS:
5.3
Affected:
up to 7.8.1
Fixed in:
7.8.2
Disclosed:
Jan 30, 2026

CVE-2025-15525 on NVD →

Ajax Load More <= 7.6.0.2 - Unauthenticated Sensitive Information Exposure

medium

The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 7.6.0.2
Fixed in:
7.6.1
Disclosed:
Sep 22, 2025

CVE-2025-59582 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.1.2

unknown

[en] The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

Affected:
up to 2.8.1.2
Fixed in:
2.8.1.2
Disclosed:
Jul 22, 2025

CVE-2015-10140 on NVD →

WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con...

CVSS:
6.4
Affected:
up to 7.4.0.1
Fixed in:
7.4.1
Disclosed:
Jun 16, 2025

CVE-2025-4775 on NVD →

Ajax Load More <= 7.3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 7.3.1.2
Fixed in:
7.3.1.3
Disclosed:
May 7, 2025

CVE-2025-47630 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] <= 7.3.1.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n/a through 7.3.1.

Affected:
up to 7.3.1.2
Fix:
No patched version reported
Disclosed:
May 7, 2025

CVE-2025-47630 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.1.3

unknown

[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribu...

Affected:
up to 7.1.3
Fixed in:
7.1.3
Disclosed:
Oct 2, 2024

CVE-2024-8505 on NVD →

WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l...

CVSS:
6.4
Affected:
up to 7.1.2
Fixed in:
7.1.3
Disclosed:
Oct 1, 2024

CVE-2024-8505 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.1.2

unknown

[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-...

Affected:
up to 7.1.2
Fixed in:
7.1.2
Disclosed:
Jun 1, 2024

CVE-2024-4711 on NVD →

WordPress Infinite Scroll – Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level...

CVSS:
6.4
Affected:
up to 7.1.1
Fixed in:
7.1.2
Disclosed:
May 31, 2024

CVE-2024-4711 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.1.0

unknown

[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the ser...

Affected:
up to 7.1.0
Fixed in:
7.1.0
Disclosed:
Apr 9, 2024

CVE-2024-1790 on NVD →

Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss...

CVSS:
4.4
Affected:
up to 7.0.1
Fixed in:
7.0.2
Disclosed:
Mar 28, 2024

CVE-2026-15295 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.0.2

unknown

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss...

Affected:
up to 7.0.2
Fixed in:
7.0.2
Disclosed:
Mar 28, 2024

Ajax Load More <= 7.0.1 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server,...

CVSS:
4.9
Affected:
up to 7.0.1
Fixed in:
7.1.0
Disclosed:
Mar 26, 2024

CVE-2024-1790 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 6.2.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney WordPress Infinite Scroll – Ajax Load More allows Stored XSS.This issue affects WordPress Infinite Scroll – Ajax Load More: from n/a through 6.1.0.1.

Affected:
up to 6.2.0
Fixed in:
6.2.0
Disclosed:
Dec 28, 2023

CVE-2023-50874 on NVD →

WordPress Infinite Scroll – Ajax Load More <= 6.1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to 6.1.0.1 (inclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 6.1.0.1
Fixed in:
6.2
Disclosed:
Dec 22, 2023

CVE-2023-50874 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.6.0.3

unknown

[en] The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 5.6.0.3
Fixed in:
5.6.0.3
Disclosed:
Mar 13, 2023

CVE-2022-4466 on NVD →

WordPress Infinite Scroll - Ajax Load More <= 5.6.0.2 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode

medium

The WordPress Infinite Scroll - Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.6.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 5.6.0.2
Fixed in:
5.6.0.3
Disclosed:
Feb 27, 2023

CVE-2022-4466 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4

unknown

[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site...

Affected:
up to 5.5.4
Fixed in:
5.5.4
Disclosed:
Sep 6, 2022

CVE-2022-2433 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4

unknown

[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents...

Affected:
up to 5.5.4
Fixed in:
5.5.4
Disclosed:
Sep 6, 2022

CVE-2022-2945 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4

unknown

[en] The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to...

Affected:
up to 5.5.4
Fixed in:
5.5.4
Disclosed:
Sep 6, 2022

CVE-2022-2943 on NVD →

Infinite Scroll – Ajax Load More <= 5.5.4 - Authenticated (Admin+) Arbitrary File Read via Directory Traversal

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4. This makes it possible administrative users to download...

CVSS:
4.9
Affected:
up to 5.5.4
Fixed in:
5.5.4.1
Disclosed:
Aug 31, 2022

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4.1

unknown

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4. This makes it possible administrative users to download...

Affected:
up to 5.5.4.1
Fixed in:
5.5.4.1
Disclosed:
Aug 31, 2022

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Cross-Site Request Forgery to PHAR Deserialization

high

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site admi...

CVSS:
7.5
Affected:
up to 5.5.3
Fixed in:
5.5.4
Disclosed:
Aug 22, 2022

CVE-2022-2433 on NVD →

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Authenticated (Admin+) Arbitrary File Read

medium

The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to down...

CVSS:
4.9
Affected:
up to 5.5.3
Fixed in:
5.5.4
Disclosed:
Aug 22, 2022

CVE-2022-2943 on NVD →

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Directory Traversal

medium

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of a...

CVSS:
4.9
Affected:
up to 5.5.3
Fixed in:
5.5.4
Disclosed:
Aug 22, 2022

CVE-2022-2945 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.3.2

unknown

[en] Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.

Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
Mar 18, 2021

CVE-2021-24140 on NVD →

Ajax Load More plugin < 5.3.2 - SQL Injection

high

Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.

CVSS:
7.2
Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
May 18, 2020

CVE-2021-24140 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.3.2

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Khanh in WordPress Ajax Load More plugin (versions <= 5.3.1).

Affected:
up to 5.3.2
Fixed in:
5.3.2
Disclosed:
May 18, 2020

Ajax Load More < 2.11.2 - Local File Inclusion

critical

The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeater' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...

CVSS:
9.8
Affected:
up to 2.11.2
Fixed in:
2.11.2
Disclosed:
Aug 15, 2016

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.11.2

unknown

Because of this vulnerability, attackers can run arbitrary PHP code. Upgrade the plugin.

Affected:
up to 2.11.2
Fixed in:
2.11.2
Disclosed:
Aug 15, 2016

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.11.2

unknown

The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeater' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...

Affected:
up to 2.11.2
Fixed in:
2.11.2
Disclosed:
Aug 15, 2016

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.1.2

unknown

Ajax Load More plugin is prone to a PHP upload vulnerability that allows to get remote code execution. Upgrade the plugin.

Affected:
up to 2.8.1.2
Fixed in:
2.8.1.2
Disclosed:
Nov 9, 2015

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.2

unknown

This vulnerability allows an attacker to upload arbitrary files to the affected computer. Upgrade the plugin.

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Oct 18, 2015

WordPress Infinite Scroll – Ajax Load More <= 2.8.1.1 - Arbitrary File Upload

high

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'alm_save_repeater()' function called via an AJAX action in versions up to, and including, 2.8.1.2. This makes it possible for authenticated attackers to upload arbitrar...

CVSS:
8.8
Affected:
up to 2.8.1.1
Fixed in:
2.8.1.2
Disclosed:
Oct 10, 2015

CVE-2015-10140 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.1.2

unknown

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'alm_save_repeater()' function called via an AJAX action in versions up to, and including, 2.8.1.2. This makes it possible for authenticated attackers to upload arbitrar...

Affected:
up to 2.8.1.2
Fixed in:
2.8.1.2
Disclosed:
Oct 10, 2015

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.0.2

unknown

Update the WordPress Ajax Load More plugin to the latest available version (at least 7.0.2). afei discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ajax Load More Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML pa...

Affected:
up to 7.0.2
Fixed in:
7.0.2

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 5.5.4

unknown

The plugin does not properly validates paths generated with user input in the alm_repeaters_export() function, which could allow high privilege users to read arbitrary files form the server (even when they should not be able to have access to any, for example in multisite setup) This is due to an incomplete fix of C...

Affected:
up to 5.5.4
Fixed in:
5.5.4

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 7.4.1

unknown
Affected:
up to 7.4.1
Fixed in:
7.4.1

CVE-2025-4775 on NVD →

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.8.1.2

unknown

Authenticated file upload in file ajax-load-more/admin/admin.php file, in the function alm_save_repeater(). The variable $f is set to a predictable PHP file path, and then the content of the variable $c is written into that file. The following code proves that this second variable is also set from untrusted input...

Affected:
up to 2.8.1.2
Fixed in:
2.8.1.2

Ajax Load More – Infinite Scroll, Load More, &amp; Lazy Load [ajax-load-more] < 2.11.2

unknown

NOTE: The victim should have the paid add-on Custom Repeater or Unlimited installed.

Affected:
up to 2.11.2
Fixed in:
2.11.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database