Connekthq

Ajax Load More

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 53.09%
  • Veröffentlicht 22.07.2025 13:20:59
  • Zuletzt bearbeitet 09.01.2026 21:16:07

The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

  • EPSS 0.13%
  • Veröffentlicht 07.05.2025 14:20:38
  • Zuletzt bearbeitet 12.05.2025 20:00:07

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n/a through 7.3.1.

  • EPSS 0.28%
  • Veröffentlicht 02.10.2024 10:15:04
  • Zuletzt bearbeitet 07.10.2024 19:26:53

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. ...

  • EPSS 0.12%
  • Veröffentlicht 01.06.2024 03:15:08
  • Zuletzt bearbeitet 21.11.2024 09:43:25

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This...

  • EPSS 0.08%
  • Veröffentlicht 28.12.2023 10:15:08
  • Zuletzt bearbeitet 21.11.2024 08:37:27

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney WordPress Infinite Scroll – Ajax Load More allows Stored XSS.This issue affects WordPress Infinite Scroll – Ajax Load More: from n/a t...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 13.03.2023 17:15:11
  • Zuletzt bearbeitet 27.02.2025 16:15:33

The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and...

Exploit
  • EPSS 1.26%
  • Veröffentlicht 06.09.2022 18:15:15
  • Zuletzt bearbeitet 05.05.2025 17:18:12

The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possibl...

Exploit
  • EPSS 0.96%
  • Veröffentlicht 06.09.2022 18:15:15
  • Zuletzt bearbeitet 21.11.2024 07:01:57

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated...

  • EPSS 3.59%
  • Veröffentlicht 06.09.2022 18:15:13
  • Zuletzt bearbeitet 21.08.2025 18:15:33

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users ...

  • EPSS 0.53%
  • Veröffentlicht 18.03.2021 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:52:27

Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.