Ajax Load More <= 7.6.0.2 - Unauthenticated Sensitive Information Exposure
Ajax Load More – Infinite Scroll, Load More, & Lazy Load
Minimum safe version
7.8.2
Update to 7.8.2 or later to address 26 fixable vulnerabilities
CVE-2025-15525
CVE-2015-10140
WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting
CVE-2025-47630
CVE-2024-8505
WordPress Ajax Load More Plugin <= 7.1.1 is vulnerable to Cross Site Scripting (XSS)
WordPress Ajax Load More Plugin <= 7.0.1 is vulnerable to Cross Site Scripting (XSS)
Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2024-1790
WordPress Ajax Load More Plugin <= 6.1.0.1 is vulnerable to Cross Site Scripting (XSS)
Ajax Load More < 5.5.4.1 - Admin+ Arbitrary File Read
WordPress Ajax Load More Plugin < 5.6.0.3 is vulnerable to Cross Site Scripting (XSS)
WordPress Infinite Scroll – Ajax Load More <= 2.8.1.1 - Arbitrary File Upload
Ajax Load More < 2.11.2 - Local File Inclusion
Infinite Scroll – Ajax Load More <= 5.5.4 - Authenticated (Admin+) Arbitrary File Read via Directory Traversal
Ajax Load More <= 2.8.1.1 - Authenticated File Upload & Deletion
Ajax Load More <= 2.11.1 - Local File Inclusion (LFI)
CVE-2022-2945
CVE-2022-2943
CVE-2022-2433
WordPress Ajax Load More Plugin < 2.8.2 - File Upload
WordPress Ajax Load More Plugin 2.8.1.1 - PHP Upload
WordPress Ajax Load More Plugin <= 2.11.1 - Local File Inclusion
WordPress Ajax Load More plugin <= 5.3.1 - Authenticated SQL Injection (SQLi) vulnerability
CVE-2021-24140