Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-15360: Ajax Load More WordPress Plugin SQL Injection Risk
CVE-2026-15360
CVE-2026-15360
Summary
An unauthenticated attacker can extract sensitive data from the database. This affects all versions of the Ajax Load More WordPress plugin before 8.0.1. To protect your site, update to version 8.0.1 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | ajax load more | < 8.0.1 |
Original title
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQ...
Original description
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
Vulnerability type
CWE-89
SQL Injection
- https://wpscan.com/vulnerability/0b5c1dd6-8bb9-45f7-8237-84a43ef53ec4/ exploit vdb-entry technical-description
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026