Impact
The Ajax Load More – Filters WordPress plugin contains a stored cross‑site scripting flaw triggered by the unfiltered "taxonomy_include_children" parameter. Because the plugin does not sanitize or escape the data before rendering it, an attacker can submit malicious JavaScript that is saved to the database and executed whenever any user visits a page that displays the injected content. The injected script can steal session cookies, deface the site, redirect users to phishing URLs, or otherwise compromise the security of the site from a browser context.
Affected Systems
All installations of the Connekt Media Ajax Load More – Filters WordPress plugin that are running version 3.4.1 or earlier are affected. The vulnerability is independent of the user role and the stored data is rendered to every site visitor who loads the affected page.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate‑to‑high severity. Because the flaw is exploitable via unauthenticated HTTP requests to a public endpoint, no privileged access is required. With no EPSS data available, the likelihood of exploitation is uncertain, but the combination of widespread plugin usage and the straightforward attack path suggests a significant business impact. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment