The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 22 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files. | |
| Title | Ajax Load More < 2.8.1.2 - Subscriber+ File Upload & Deletion | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-07-22T13:44:53.208Z
Reserved: 2025-07-22T13:07:51.745Z
Link: CVE-2015-10140
Updated: 2025-07-22T13:44:24.545Z
Status : Awaiting Analysis
Published: 2025-07-22T14:15:32.590
Modified: 2025-07-25T15:29:44.523
Link: CVE-2015-10140
No data.
OpenCVE Enrichment
No data.