Ajax Load More <= 8.0.0 - Unauthenticated SQL Injection
high
The Ajax Load More plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries i...
- CVSS:
- 7.5
- Affected:
- up to 8.0.0
- Fixed in:
- 8.0.1
- Disclosed:
- Jul 29, 2026
CVE-2026-15360 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load < 7.8.4 - Unauthenticated Stored Cross-Site Scripting
high
The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execu...
- CVSS:
- 7.2
- Affected:
- up to 7.8.4
- Fixed in:
- 7.8.4
- Disclosed:
- Jun 11, 2026
CVE-2026-6495 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 7.8.2
unknown
[en] The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles an...
- Affected:
- up to 7.8.2
- Fixed in:
- 7.8.2
- Disclosed:
- Jan 31, 2026
CVE-2025-15525 on NVD →
Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure
medium
The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles and exc...
- CVSS:
- 5.3
- Affected:
- up to 7.8.1
- Fixed in:
- 7.8.2
- Disclosed:
- Jan 30, 2026
CVE-2025-15525 on NVD →
Ajax Load More <= 7.6.0.2 - Unauthenticated Sensitive Information Exposure
medium
The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 7.6.0.2
- Fixed in:
- 7.6.1
- Disclosed:
- Sep 22, 2025
CVE-2025-59582 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.8.1.2
unknown
[en] The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.
- Affected:
- up to 2.8.1.2
- Fixed in:
- 2.8.1.2
- Disclosed:
- Jul 22, 2025
CVE-2015-10140 on NVD →
WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con...
- CVSS:
- 6.4
- Affected:
- up to 7.4.0.1
- Fixed in:
- 7.4.1
- Disclosed:
- Jun 16, 2025
CVE-2025-4775 on NVD →
Ajax Load More <= 7.3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 7.3.1.2
- Fixed in:
- 7.3.1.3
- Disclosed:
- May 7, 2025
CVE-2025-47630 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] <= 7.3.1.2 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n/a through 7.3.1.
- Affected:
- up to 7.3.1.2
- Fix:
- No patched version reported
- Disclosed:
- May 7, 2025
CVE-2025-47630 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 7.1.3
unknown
[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contribu...
- Affected:
- up to 7.1.3
- Fixed in:
- 7.1.3
- Disclosed:
- Oct 2, 2024
CVE-2024-8505 on NVD →
WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.3
- Disclosed:
- Oct 1, 2024
CVE-2024-8505 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 7.1.2
unknown
[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-...
- Affected:
- up to 7.1.2
- Fixed in:
- 7.1.2
- Disclosed:
- Jun 1, 2024
CVE-2024-4711 on NVD →
WordPress Infinite Scroll – Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 7.1.1
- Fixed in:
- 7.1.2
- Disclosed:
- May 31, 2024
CVE-2024-4711 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 7.1.0
unknown
[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the ser...
- Affected:
- up to 7.1.0
- Fixed in:
- 7.1.0
- Disclosed:
- Apr 9, 2024
CVE-2024-1790 on NVD →
Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss...
- CVSS:
- 4.4
- Affected:
- up to 7.0.1
- Fixed in:
- 7.0.2
- Disclosed:
- Mar 28, 2024
CVE-2026-15295 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 7.0.2
unknown
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss...
- Affected:
- up to 7.0.2
- Fixed in:
- 7.0.2
- Disclosed:
- Mar 28, 2024
Ajax Load More <= 7.0.1 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server,...
- CVSS:
- 4.9
- Affected:
- up to 7.0.1
- Fixed in:
- 7.1.0
- Disclosed:
- Mar 26, 2024
CVE-2024-1790 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 6.2.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney WordPress Infinite Scroll – Ajax Load More allows Stored XSS.This issue affects WordPress Infinite Scroll – Ajax Load More: from n/a through 6.1.0.1.
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.0
- Disclosed:
- Dec 28, 2023
CVE-2023-50874 on NVD →
WordPress Infinite Scroll – Ajax Load More <= 6.1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to 6.1.0.1 (inclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 6.1.0.1
- Fixed in:
- 6.2
- Disclosed:
- Dec 22, 2023
CVE-2023-50874 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.6.0.3
unknown
[en] The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 5.6.0.3
- Fixed in:
- 5.6.0.3
- Disclosed:
- Mar 13, 2023
CVE-2022-4466 on NVD →
WordPress Infinite Scroll - Ajax Load More <= 5.6.0.2 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode
medium
The WordPress Infinite Scroll - Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.6.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...
- CVSS:
- 6.4
- Affected:
- up to 5.6.0.2
- Fixed in:
- 5.6.0.3
- Disclosed:
- Feb 27, 2023
CVE-2022-4466 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.5.4
unknown
[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site...
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4
- Disclosed:
- Sep 6, 2022
CVE-2022-2433 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.5.4
unknown
[en] The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents...
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4
- Disclosed:
- Sep 6, 2022
CVE-2022-2945 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.5.4
unknown
[en] The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to...
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4
- Disclosed:
- Sep 6, 2022
CVE-2022-2943 on NVD →
Infinite Scroll – Ajax Load More <= 5.5.4 - Authenticated (Admin+) Arbitrary File Read via Directory Traversal
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4. This makes it possible administrative users to download...
- CVSS:
- 4.9
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4.1
- Disclosed:
- Aug 31, 2022
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.5.4.1
unknown
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4. This makes it possible administrative users to download...
- Affected:
- up to 5.5.4.1
- Fixed in:
- 5.5.4.1
- Disclosed:
- Aug 31, 2022
WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Cross-Site Request Forgery to PHAR Deserialization
high
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wrapper, granted they can trick a site admi...
- CVSS:
- 7.5
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.4
- Disclosed:
- Aug 22, 2022
CVE-2022-2433 on NVD →
WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Authenticated (Admin+) Arbitrary File Read
medium
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to down...
- CVSS:
- 4.9
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.4
- Disclosed:
- Aug 22, 2022
CVE-2022-2943 on NVD →
WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Directory Traversal
medium
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of a...
- CVSS:
- 4.9
- Affected:
- up to 5.5.3
- Fixed in:
- 5.5.4
- Disclosed:
- Aug 22, 2022
CVE-2022-2945 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.3.2
unknown
[en] Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- Mar 18, 2021
CVE-2021-24140 on NVD →
Ajax Load More plugin < 5.3.2 - SQL Injection
high
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.
- CVSS:
- 7.2
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- May 18, 2020
CVE-2021-24140 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.3.2
unknown
Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Khanh in WordPress Ajax Load More plugin (versions <= 5.3.1).
- Affected:
- up to 5.3.2
- Fixed in:
- 5.3.2
- Disclosed:
- May 18, 2020
Ajax Load More < 2.11.2 - Local File Inclusion
critical
The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeater' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...
- CVSS:
- 9.8
- Affected:
- up to 2.11.2
- Fixed in:
- 2.11.2
- Disclosed:
- Aug 15, 2016
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.11.2
unknown
Because of this vulnerability, attackers can run arbitrary PHP code.
Upgrade the plugin.
- Affected:
- up to 2.11.2
- Fixed in:
- 2.11.2
- Disclosed:
- Aug 15, 2016
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.11.2
unknown
The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeater' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access contr...
- Affected:
- up to 2.11.2
- Fixed in:
- 2.11.2
- Disclosed:
- Aug 15, 2016
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.8.1.2
unknown
Ajax Load More plugin is prone to a PHP upload vulnerability that allows to get remote code execution.
Upgrade the plugin.
- Affected:
- up to 2.8.1.2
- Fixed in:
- 2.8.1.2
- Disclosed:
- Nov 9, 2015
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.8.2
unknown
This vulnerability allows an attacker to upload arbitrary files to the affected computer.
Upgrade the plugin.
- Affected:
- up to 2.8.2
- Fixed in:
- 2.8.2
- Disclosed:
- Oct 18, 2015
WordPress Infinite Scroll – Ajax Load More <= 2.8.1.1 - Arbitrary File Upload
high
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'alm_save_repeater()' function called via an AJAX action in versions up to, and including, 2.8.1.2. This makes it possible for authenticated attackers to upload arbitrar...
- CVSS:
- 8.8
- Affected:
- up to 2.8.1.1
- Fixed in:
- 2.8.1.2
- Disclosed:
- Oct 10, 2015
CVE-2015-10140 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.8.1.2
unknown
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'alm_save_repeater()' function called via an AJAX action in versions up to, and including, 2.8.1.2. This makes it possible for authenticated attackers to upload arbitrar...
- Affected:
- up to 2.8.1.2
- Fixed in:
- 2.8.1.2
- Disclosed:
- Oct 10, 2015
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 7.0.2
unknown
Update the WordPress Ajax Load More plugin to the latest available version (at least 7.0.2).
afei discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ajax Load More Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML pa...
- Affected:
- up to 7.0.2
- Fixed in:
- 7.0.2
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 5.5.4
unknown
The plugin does not properly validates paths generated with user input in the alm_repeaters_export() function, which could allow high privilege users to read arbitrary files form the server (even when they should not be able to have access to any, for example in multisite setup)
This is due to an incomplete fix of C...
- Affected:
- up to 5.5.4
- Fixed in:
- 5.5.4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 7.4.1
unknown
- Affected:
- up to 7.4.1
- Fixed in:
- 7.4.1
CVE-2025-4775 on NVD →
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.8.1.2
unknown
Authenticated file upload in file ajax-load-more/admin/admin.php file, in the function alm_save_repeater().
The variable $f is set to a predictable PHP file path, and then the content of the variable $c is written into that file.
The following code proves that this second variable is also set from untrusted input...
- Affected:
- up to 2.8.1.2
- Fixed in:
- 2.8.1.2
Ajax Load More – Infinite Scroll, Load More, & Lazy Load [ajax-load-more] < 2.11.2
unknown
NOTE: The victim should have the paid add-on Custom Repeater or Unlimited installed.
- Affected:
- up to 2.11.2
- Fixed in:
- 2.11.2