CVE-2026-15295
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
- EPSS probability
- 0.24%
- CWE
- CWE-692
- Published
- 2026-07-10
- Last modified
- 2026-07-14
Affected products
- dcooney Ajax Load More – Infinite Scroll, Load More, & Lazy Load
Weakness type
Related vulnerabilities
- CVE-2026-71478 — league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
- CVE-2024-23569 — HCL Aftermarket EPC is vulnerable to attack since the server is not configured with...
- CVE-2024-42214 — HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web...
- CVE-2025-20240 — A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an...
- CVE-2025-53904 — The Scratch Channel Has Potential Reflected Cross-Site Scripting (XSS) Vulnerability
- CVE-2025-49590 — CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
- CVE-2024-52305 — UnoPim Stored XSS : Cookie hijacking through Create User function
- CVE-2023-26047 — teler-waf contains detection rule bypass via entities payload