The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database. This vulnerability affects WordPress administrators and users of the Ajax Load More plugin, as well as security teams responsible for monitoring and prote [truncated]
A reflected cross-site scripting (XSS) vulnerability exists in the Ajax Load More WordPress plugin before version 7.8.4. The plugin fails to sanitize and escape a parameter before rendering it in page output, enabling attackers to inject malicious scripts. Successful exploitation could compromise high-privilege user sessions, including administrators. The vulnerability carries a HIGH severity CVSS score o [truncated]