Extension WordPress
Vulnérabilités Ajax Load More – Infinite Scroll, Load More, & Lazy Load
Cette page rassemble les failles publiées pour Ajax Load More – Infinite Scroll, Load More, & Lazy Load, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Ajax Load More – Infinite Scroll, Load More, & Lazy Load
18 fiches
Ajax Load More – Infinite Scroll, Load More, & Lazy Load < 7.8.4 – Unauthenticated Stored Cross-Site Scripting
The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.8.4 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 7.8.4)
7.8.4
11/06/2026
Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 – Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure
The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1.…
*-7.8.1
7.8.2
30/01/2026
Ajax Load More <= 7.6.0.2 – Unauthenticated Sensitive Information Exposure
The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
*-7.6.0.2
7.6.1
22/09/2025
WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 – Authenticated(Contributor+) Stored Cross-Site Scripting
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping.…
*-7.4.0.1
7.4.1
16/06/2025
Ajax Load More <= 7.3.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-7.3.1.2
7.3.1.3
07/05/2025
WordPress Infinite Scroll – Ajax Load More <= 7.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This…
*-7.1.2
7.1.3
01/10/2024
WordPress Infinite Scroll – Ajax Load More <= 7.1.1 – Authenticated (Contributor+) Cross-Site Scripting
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes…
*-7.1.1
7.1.2
31/05/2024
Ajax Load More <= 7.0.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes…
*-7.0.1
7.0.2
28/03/2024
Ajax Load More <= 7.0.1 – Authenticated (Admin+) Directory Traversal to Arbitrary File Read
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access…
*-7.0.1
7.1.0
26/03/2024
WordPress Infinite Scroll – Ajax Load More <= 6.1.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to 6.1.0.1 (inclusive) due to insufficient input sanitization and output escaping. This makes…
*-6.1.0.1
6.2
22/12/2023
WordPress Infinite Scroll – Ajax Load More <= 5.6.0.2 – Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.6.0.2 due to insufficient input sanitization and output escaping on user…
*-5.6.0.2
5.6.0.3
27/02/2023
Infinite Scroll – Ajax Load More <= 5.5.4 – Authenticated (Admin+) Arbitrary File Read via Directory Traversal
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4.…
*-5.5.4
5.5.4.1
31/08/2022
WordPress Infinite Scroll – Ajax Load More <= 5.5.3 – Cross-Site Request Forgery to PHAR Deserialization
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call…
*-5.5.3
5.5.4
22/08/2022
WordPress Infinite Scroll – Ajax Load More <= 5.5.3 – Directory Traversal
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated…
*-5.5.3
5.5.4
22/08/2022
WordPress Infinite Scroll – Ajax Load More <= 5.5.3 – Authenticated (Admin+) Arbitrary File Read
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible…
*-5.5.3
5.5.4
22/08/2022
Ajax Load More plugin < 5.3.2 – SQL Injection
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.
[*, 5.3.2)
5.3.2
18/05/2020
Ajax Load More < 2.11.2 – Local File Inclusion
The Ajax Load More plugin for WordPress is vulnerable to Local File Inclusion in versions before 2.11.2 via the 'repeater' parameter. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of…
[*, 2.11.2)
2.11.2
15/08/2016
WordPress Infinite Scroll – Ajax Load More <= 2.8.1.1 – Arbitrary File Upload
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'alm_save_repeater()' function called via an AJAX action in versions up to, and including,…
*-2.8.1.1
2.8.1.2
10/10/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.