CVE-2026-15295

Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

2024-03-28 00:00
afei

Strategic Overview

Status
Patched in 7.0.2
Affected Version
<= 7.0.1
CVSS
4.4Medium
Weakness type
CWE-692 · Incomplete Denylist to Cross-Site Scripting
CVE
CVE-2026-15295
View all Ajax Load More – Infinite Scroll, Load More, & Lazy Load vulnerabilities

At a glance

CVE-2026-15295 is a medium-severity Incomplete Denylist to Cross-Site Scripting vulnerability in the Ajax Load More WordPress plugin, affecting versions <= 7.0.1. It carries a CVSS score of 4.4 (reachable over the network). Exploitation requires an authenticated account at Administrator level or above. The issue is fixed in version 7.0.2; sites on affected versions should update now. Disclosed March 2024, reported by afei.

Vulnerability Overview

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, and no interaction from a victim user.

CWE-692: Incomplete Denylist to Cross-Site Scripting

The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.

Remediation

Update to version 7.0.2, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: Ajax Load More 7.0.2 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C