top of page
perceptive_background_267k.jpg

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated att…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 17:04:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

A critical SQL injection vulnerability has been identified in the Ajax Load More WordPress plugin before version 8.0.1. The plugin fails to properly sanitize and escape a parameter before incorporating it into a SQL query. This flaw allows unauthenticated attackers to perform time-based blind SQL injection attacks. Exploitation of this vulnerability can result in unauthorized extraction of sensitive data from the underlying database. No authentication is required to exploit this vulnerability, significantly increasing its risk profile. The issue has been addressed in version 8.0.1 of the plugin. WordPress site administrators using this plugin are strongly advised to update immediately.

Technical details

Mitigation steps:

Affected products:

Ajax Load More WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page