PT-2026-5501 · WordPress · Ajax Load More
Angus Girvan
·
Publicado
2026-01-31
·
Atualizado
2026-01-31
·
CVE-2025-15525
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress versions through 7.8.1
Description
The Ajax Load More plugin for WordPress has a flaw where data access isn’t properly controlled. Specifically, the
parse custom args() function lacks correct authorization checks. This allows attackers who haven’t logged in to view titles and excerpts of posts that are private, drafts, pending publication, scheduled, or in the trash.Recommendations
Update to a version newer than 7.8.1.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ajax Load More