CVE-2026-15360: Unknown AJAX Load More

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.

Affected products

  • Unknown AJAX Load More: before 8.0.1 (fixed in 8.0.1)

Published 2026-08-05. Last modified 2026-08-26.