CVE-2015-10140 Information
Jul 23, 2025
cve
Description
The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions allowing any authenticated users such as subscriber to upload and delete arbitrary files.
Reference
https://wpscan.com/vulnerability/9f0c926e-0609-4c89-a724-88e16bcfa82a
Related CNNVD
CNNVD-202507-2878 (Published: 2025-07-22)
Share on: