PT-2022-16612 · WordPress · Wordpress Infinite Scroll – Ajax Load More
Rasoul Jahanshahi
·
Published
2022-09-06
·
Updated
2025-08-21
·
CVE-2022-2433
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress Infinite Scroll – Ajax Load More plugin versions up to, and including 5.5.3
Description
The issue allows deserialization of untrusted input via the
alm repeaters export parameter. This enables unauthenticated users to potentially call files using a PHAR wrapper if they can trick a site administrator into performing a specific action, such as clicking on a link. The action must deserialize and call arbitrary PHP Objects, which can be used for malicious purposes if a POP chain is present. Additionally, the attacker must successfully upload a file containing the serialized payload.Recommendations
For WordPress Infinite Scroll – Ajax Load More plugin versions up to, and including 5.5.3, consider disabling the
alm repeaters export parameter until a patch is available to prevent deserialization of untrusted input. Restrict access to the plugin's functionality to minimize the risk of exploitation, especially in scenarios where an attacker could trick an administrator into performing actions that lead to deserialization of malicious payloads.Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Infinite Scroll – Ajax Load More