Impact
The WordPress Ajax Load More plugin before version 8.0.1 fails to sanitize the custom_args parameter before including it in an SQL query. Attackers can exploit this flaw with a time‑based blind SQL injection to read arbitrary database tables, exposing usernames, passwords, and other sensitive information. This constitutes a significant confidentiality breach and aligns with SQL injection weaknesses.
Affected Systems
WordPress sites running Ajax Load More plugin prior to version 8.0.1 are affected. The vulnerability exists in any installation of the plugin where the custom_args endpoint is reachable by unauthenticated users.
Risk and Exploitability
Because the vulnerability is unauthenticated and requires only a crafted HTTP request to the plugin’s endpoint, an attacker can exploit it from any network location that can reach the site. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, but the potential impact of unrestricted data extraction, combined with the low attack effort, yields a high risk classification.
OpenCVE Enrichment