CVE-2015-10140: Connekthq AJAX Load More

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

Affected products

  • Connekthq AJAX Load More: before 2.8.1.2 (fixed in 2.8.1.2)

Published 2025-07-22. Last modified 2026-06-17.