The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.
Metrics
Affected Vendors & Products
References
History
Fri, 02 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Connekthq
Connekthq ajax Load More |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:connekthq:ajax_load_more:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Connekthq
Connekthq ajax Load More |
Tue, 22 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 22 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files. | |
| Title | Ajax Load More < 2.8.1.2 - Subscriber+ File Upload & Deletion | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-07-22T13:44:53.208Z
Reserved: 2025-07-22T13:07:51.745Z
Link: CVE-2015-10140
Updated: 2025-07-22T13:44:24.545Z
Status : Analyzed
Published: 2025-07-22T14:15:32.590
Modified: 2026-01-02T21:02:52.147
Link: CVE-2015-10140
No data.
OpenCVE Enrichment
No data.