Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-15360: Ajax Load More WordPress Plugin SQL Injection Risk

CVE-2026-15360 CVE-2026-15360
Summary

An unauthenticated attacker can extract sensitive data from the database. This affects all versions of the Ajax Load More WordPress plugin before 8.0.1. To protect your site, update to version 8.0.1 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
unknown ajax load more < 8.0.1
Original title
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQ...
Original description
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
Vulnerability type
CWE-89 SQL Injection
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026