


Perceptive Security
SOC/SIEM Consultancy

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated att…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 17:04:40
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A critical SQL injection vulnerability has been identified in the Ajax Load More WordPress plugin before version 8.0.1. The plugin fails to properly sanitize and escape a parameter before incorporating it into a SQL query. This flaw allows unauthenticated attackers to perform time-based blind SQL injection attacks. Exploitation of this vulnerability can result in unauthorized extraction of sensitive data from the underlying database. No authentication is required to exploit this vulnerability, significantly increasing its risk profile. The issue has been addressed in version 8.0.1 of the plugin. WordPress site administrators using this plugin are strongly advised to update immediately.
Technical details
Mitigation steps:
Affected products:
Ajax Load More WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15360
https://wpscan.com/vulnerability/0b5c1dd6-8bb9-45f7-8237-84a43ef53ec4/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
