{"id":"CVE-2026-15360","published":"2026-08-05T07:16:35.123","lastModified":"2026-08-05T16:16:50.597","description":"The Ajax Load More  WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/0b5c1dd6-8bb9-45f7-8237-84a43ef53ec4/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a time-based blind SQL injection vulnerability in the Ajax Load More WordPress plugin before version 8.0.1, allowing unauthenticated attackers to extract sensitive data from the database. This matters because it can lead to data breaches and compromise user information.","exploitability":"Exploitation requires access to the affected plugin's parameter input and knowledge of SQL injection techniques; no authentication is needed but technical expertise is required.","blast_radius":"If exploited, attackers could extract sensitive data such as user credentials, personal information, or other confidential content stored in the database, significantly impacting site security and user trust.","remediation":"Update to Ajax Load More version 8.0.1 or later to address the vulnerability and ensure proper parameter sanitization and escaping.","tags":["sql-injection","data-extraction","wordpress","blind-sql"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:44:54.249Z"}}