Vulnerability Description
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-15360?
CVE-2026-15360 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL i...
How severe is CVE-2026-15360?
CVE-2026-15360 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-15360?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.