Impact
The Ajax Load More WordPress plugin stores arbitrary script code entered into its admin settings without proper sanitization or escaping. An attacker who can log in with Administrator privileges or higher can inject JavaScript that will run in the browsers of any user who views a page containing the compromised setting. The flaw is only present in multisite installations and when the unfiltered_html capability is disabled.
Affected Systems
All installations of the Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin with versions up to and including 7.0.1 are affected. The vulnerability resides in the admin interface used to configure the plugin, and therefore only sites that enable these settings and have administrator accounts can be targeted.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity; the EPSS score is < 1% and the issue is not listed in CISA’s KEV catalog. Exploitation requires an attacker already possesses admin or higher credentials to inject the malicious code. Once injected, the payload is delivered to every visitor who loads a page containing the compromised setting, making the attack straightforward for privileged users while the impact on visitors is limited to the injected client‑side code.
OpenCVE Enrichment