WordPress · Ajax Load More · CVE-2026-15295
**Name of the Vulnerable Software and Affected Versions**
Ajax Load More versions prior to 7.0.2
**Description**
The WordPress Infinite Scroll – Ajax Load More plugin contains a Stored Cross-Site Scripting issue within the admin settings. This occurs due to insufficient input sanitization and output escaping, allowing authenticated attackers with administrator-level permissions or higher to inject arbitrary web scripts into pages. These scripts execute when a user accesses the affected page. This issue specifically impacts multi-site installations and environments where `unfiltered html` has been disabled.
**Recommendations**
Update the plugin to version 7.0.2 or later.