Junglewise Threat Intelligence

CVE-2026-15295: WordPress Ajax Load More Stored XSS in admin settings

CVE-2026-15295 · Severity: medium · CVSS 4.4 · Published 2026-07-10

Executive brief

The Ajax Load More plugin for WordPress, which provides infinite scrolling and lazy loading features, contains a security flaw in its administrative settings. This vulnerability allows high-level users (administrators) to save malicious scripts into the website's configuration. These scripts then run automatically in the browsers of other users who visit the site, potentially leading to unauthorized actions or data theft. This issue primarily impacts WordPress multi-site networks or specific configurations where standard security restrictions on HTML content have been relaxed.

Technical details

The Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the administrative settings. An authenticated attacker with administrator-level permissions can inject arbitrary web scripts into the database. These scripts execute when a user accesses the affected pages. The vulnerability is exploitable in multi-site installations or environments where the 'unfiltered_html' capability is disabled for administrators. The issue is addressed in versions following 7.0.1.

Affected products

  • dcooney Ajax Load More – Infinite Scroll, Load More, & Lazy Load <= 7.0.1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References