Plugin Vulnerability Hub
Plugin 17 known issues Latest disclosed Jan 30, 2026

Ajax Load More – Infinite Scroll, Load More, & Lazy Load Vulnerabilities

Review known vulnerability records for the WordPress plugin Ajax Load More – Infinite Scroll, Load More, & Lazy Load (`ajax-load-more`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-15525, CVE-2025-59582 and CVE-2025-4775, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
17
High or Critical
4
Patch Coverage
100%
Last Updated
Jan 31, 2026
Priority CVE Quick Links

Fast paths into Ajax Load More – Infinite Scroll, Load More, & Lazy Load CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
14
CVE-2015-10140 High 2.8.1.2
CVE-2015-10140 Ajax Load More – Infinite Scroll, Load More, & Lazy Load Remote Code Execution

WordPress Infinite Scroll – Ajax Load More <= 2.8.1.1 - Arbitrary File Upload

CVE-2022-2433 High 5.5.4
CVE-2022-2433 Ajax Load More – Infinite Scroll, Load More, & Lazy Load Cross-Site Request Forgery

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Cross-Site Request Forgery to PHAR Deserialization

CVE-2021-24140 High 5.3.2
CVE-2021-24140 Ajax Load More – Infinite Scroll, Load More, & Lazy Load SQL Injection

Ajax Load More plugin < 5.3.2 - SQL Injection

CVE-2025-4775 Medium 7.4.1
CVE-2025-4775 Ajax Load More – Infinite Scroll, Load More, & Lazy Load Stored Cross-Site Scripting

WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting

CVE-2025-47630 Medium 7.3.1.3
CVE-2025-47630 Ajax Load More – Infinite Scroll, Load More, & Lazy Load Stored Cross-Site Scripting

Ajax Load More <= 7.3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

CVE-2024-8505 Medium 7.1.3
CVE-2024-8505 Ajax Load More – Infinite Scroll, Load More, & Lazy Load Stored Cross-Site Scripting

WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter

CVE-2024-4711 Medium 7.1.2
CVE-2024-4711 Ajax Load More – Infinite Scroll, Load More, & Lazy Load Stored Cross-Site Scripting

WordPress Infinite Scroll – Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting

CVE-2023-50874 Medium 6.2
CVE-2023-50874 Ajax Load More – Infinite Scroll, Load More, & Lazy Load Stored Cross-Site Scripting

WordPress Infinite Scroll – Ajax Load More <= 6.1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Ajax Load More – Infinite Scroll, Load More, & Lazy Load so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
17 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 3 high severity findings.
Recent CVEs
CVE-2025-15525, CVE-2025-59582 and CVE-2025-4775
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Ajax Load More – Infinite Scroll, Load More, & Lazy Load

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-15525
CVE-2025-15525: Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure

The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticate...

Published
Jan 30, 2026
Patched Release
7.8.2
Affected Versions
Versions up to 7.8.1
Next Step
Update to 7.8.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-59582
CVE-2025-59582: Ajax Load More <= 7.6.0.2 - Unauthenticated Sensitive Information Exposure

The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Published
Sep 22, 2025
Patched Release
7.6.1
Affected Versions
Versions up to 7.6.0.2
Next Step
Update to 7.6.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-4775
CVE-2025-4775: WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possib...

Published
Jun 16, 2025
Patched Release
7.4.1
Affected Versions
Versions up to 7.4.0.1
Next Step
Update to 7.4.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-47630
CVE-2025-47630: Ajax Load More <= 7.3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

Published
May 07, 2025
Patched Release
7.3.1.3
Affected Versions
Versions up to 7.3.1.2
Next Step
Update to 7.3.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-8505
CVE-2024-8505: WordPress Infinite Scroll - Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up to, and including, 7.1.2 due to insufficient input sanitization and output escaping. This makes it possible for aut...

Published
Oct 01, 2024
Patched Release
7.1.3
Affected Versions
Versions up to 7.1.2
Next Step
Update to 7.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4711
CVE-2024-4711: WordPress Infinite Scroll – Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ajax_load_more shortcode in versions up to, and including, 7.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authent...

Published
May 31, 2024
Patched Release
7.1.2
Affected Versions
Versions up to 7.1.1
Next Step
Update to 7.1.2 or newer if supported.
Plugin Medium Patched: Yes
Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

Published
Mar 28, 2024
Patched Release
7.0.2
Affected Versions
Versions up to 7.0.1
Next Step
Update to 7.0.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-1790
CVE-2024-1790: Ajax Load More <= 7.0.1 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 7.0.1 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the con...

Published
Mar 26, 2024
Patched Release
7.1.0
Affected Versions
Versions up to 7.0.1
Next Step
Update to 7.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-50874
CVE-2023-50874: WordPress Infinite Scroll – Ajax Load More <= 6.1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to 6.1.0.1 (inclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Published
Dec 22, 2023
Patched Release
6.2
Affected Versions
Versions up to 6.1.0.1
Next Step
Update to 6.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-4466
CVE-2022-4466: WordPress Infinite Scroll - Ajax Load More <= 5.6.0.2 - Authenticated (Contributor+) Stored Cross Site Scripting via Shortcode

The WordPress Infinite Scroll - Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 5.6.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This ma...

Published
Feb 27, 2023
Patched Release
5.6.0.3
Affected Versions
Versions up to 5.6.0.2
Next Step
Update to 5.6.0.3 or newer if supported.
Plugin Medium Patched: Yes
Infinite Scroll – Ajax Load More <= 5.5.4 - Authenticated (Admin+) Arbitrary File Read via Directory Traversal

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via directory traversal due to insufficient file path validation returned via the alm_repeaters_export() function in versions up to, and including, 5.5.4. This makes it po...

Published
Aug 31, 2022
Patched Release
5.5.4.1
Affected Versions
Versions up to 5.5.4
Next Step
Update to 5.5.4.1 or newer if supported.
Plugin High Patched: Yes CVE-2022-2433
CVE-2022-2433: WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Cross-Site Request Forgery to PHAR Deserialization

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR wra...

Published
Aug 22, 2022
Patched Release
5.5.4
Affected Versions
Versions up to 5.5.3
Next Step
Update to 5.5.4 or newer if supported.