Extension WordPress

Vulnérabilités Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Cette page rassemble les failles publiées pour Ajax Load More – Infinite Scroll, Load More, & Lazy Load, leurs plages de versions affectées et les correctifs signalés dans la base locale.

18Vulnérabilités
1Critiques
18Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Ajax Load More – Infinite Scroll, Load More, & Lazy Load

18 fiches

CVE-2026-6495 Élevée · 7,2
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Ajax Load More – Infinite Scroll, Load More, & Lazy Load < 7.8.4 – Unauthenticated Stored Cross-Site Scripting

The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 7.8.4 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

[*, 7.8.4)

Correctif

7.8.4

Publication

11/06/2026

CVE-2025-15525 Moyenne · 5,3
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 – Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure

The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1.…

Versions affectées

*-7.8.1

Correctif

7.8.2

Publication

30/01/2026

CVE-2025-59582 Moyenne · 5,3
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Ajax Load More <= 7.6.0.2 – Unauthenticated Sensitive Information Exposure

The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Versions affectées

*-7.6.0.2

Correctif

7.6.1

Publication

22/09/2025

CVE-2025-4775 Moyenne · 6,4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 – Authenticated(Contributor+) Stored Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping.…

Versions affectées

*-7.4.0.1

Correctif

7.4.1

Publication

16/06/2025

CVE-2025-47630 Moyenne · 6,4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Ajax Load More <= 7.3.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…

Versions affectées

*-7.3.1.2

Correctif

7.3.1.3

Publication

07/05/2025

CVE-2024-8505 Moyenne · 6,4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 7.1.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-7.1.2

Correctif

7.1.3

Publication

01/10/2024

CVE-2024-4711 Moyenne · 6,4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 7.1.1 – Authenticated (Contributor+) Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-7.1.1

Correctif

7.1.2

Publication

31/05/2024

CVE-2026-15295 Moyenne · 4,4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Ajax Load More <= 7.0.1 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-7.0.1

Correctif

7.0.2

Publication

28/03/2024

CVE-2024-1790 Moyenne · 4,9
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Ajax Load More <= 7.0.1 – Authenticated (Admin+) Directory Traversal to Arbitrary File Read

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access…

Versions affectées

*-7.0.1

Correctif

7.1.0

Publication

26/03/2024

CVE-2023-50874 Moyenne · 6,4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 6.1.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to 6.1.0.1 (inclusive) due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-6.1.0.1

Correctif

6.2

Publication

22/12/2023

CVE-2022-4466 Moyenne · 6,4
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 5.6.0.2 – Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.6.0.2 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-5.6.0.2

Correctif

5.6.0.3

Publication

27/02/2023

Vulnérabilité Moyenne · 4,9
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Infinite Scroll – Ajax Load More <= 5.5.4 – Authenticated (Admin+) Arbitrary File Read via Directory Traversal

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4.…

Versions affectées

*-5.5.4

Correctif

5.5.4.1

Publication

31/08/2022

CVE-2022-2433 Élevée · 7,5
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 – Cross-Site Request Forgery to PHAR Deserialization

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call…

Versions affectées

*-5.5.3

Correctif

5.5.4

Publication

22/08/2022

CVE-2022-2945 Moyenne · 4,9
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 – Directory Traversal

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated…

Versions affectées

*-5.5.3

Correctif

5.5.4

Publication

22/08/2022

CVE-2022-2943 Moyenne · 4,9
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 – Authenticated (Admin+) Arbitrary File Read

The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible…

Versions affectées

*-5.5.3

Correctif

5.5.4

Publication

22/08/2022

CVE-2015-10140 Élevée · 8,8
Ajax Load More – Infinite Scroll, Load More, & Lazy Load

WordPress Infinite Scroll – Ajax Load More <= 2.8.1.1 – Arbitrary File Upload

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'alm_save_repeater()' function called via an AJAX action in versions up to, and including,…

Versions affectées

*-2.8.1.1

Correctif

2.8.1.2

Publication

10/10/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités