CVE-2026-15360: Unknown AJAX Load More
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
Affected products
- Unknown AJAX Load More: before 8.0.1 (fixed in 8.0.1)
Published 2026-08-05. Last modified 2026-08-26.