PT-2022-19624 · WordPress · Wordpress Infinite Scroll – Ajax Load More

Muhammad Zeeshan

·

Published

2022-09-06

·

Updated

2024-01-11

·

CVE-2022-2945

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress Infinite Scroll – Ajax Load More plugin versions up to, and including, 5.5.3
Description The issue allows authenticated attackers with administrative permissions to read the contents of arbitrary files on the server, potentially containing sensitive information, via the type parameter in the alm get layout() function.
Recommendations For WordPress Infinite Scroll – Ajax Load More plugin versions up to, and including, 5.5.3, consider updating to a version that fixes this issue, as no specific workaround is provided for these versions. As a temporary mitigation measure, restrict access to the alm get layout() function to minimize the risk of exploitation. Avoid using the type parameter in the affected function until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-2945

Affected Products

Wordpress Infinite Scroll – Ajax Load More