CVE-2026-15360
9.1 CRITICALPublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw is a time-based blind SQL injection vulnerability in the Ajax Load More WordPress plugin before 8.0.1, allowing unauthenticated attackers to extract sensitive data from the database. This matters because it can lead to data breaches and loss of confidentiality.
- Exploitability
- Exploitation is moderately hard as it requires the attacker to craft a specific SQL injection payload, but preconditions include the plugin being active and the database being accessible via the web interface.
- Blast radius
- If exploited, the impact is high as it could lead to the exposure of sensitive data, potentially affecting all users of the WordPress site.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 8.0.1 or later of the Ajax Load More plugin.
sql-injectionwebwordpress
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-89
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2022-4997
- HIGHCVE-2026-15918
- MEDIUMCVE-2026-15941
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-63564
- CRITICALCVE-2026-12718
- MEDIUMCVE-2026-14872
Related by shared AI tags and CWE weakness class. Browse the full archive.