CVE-2026-15360

Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args

Title source: cna
STIX 2.1

Description

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/0b5c1dd6-8bb9-45f7-8237-84a43ef53ec4/

Scores

EPSS 0.0032
EPSS Percentile 24.9%

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

Status published
Products (1)
None/Ajax Load More < 8.0.1
Published Aug 05, 2026
Tracked Since Aug 05, 2026