Vulnerabilities (CVE)

Filtered by vendor Connekthq Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-2945 1 Connekthq 1 Ajax Load More 2024-01-11 N/A 2.7 LOW
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.
CVE-2023-50874 1 Connekthq 1 Ajax Load More 2024-01-04 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney WordPress Infinite Scroll – Ajax Load More allows Stored XSS.This issue affects WordPress Infinite Scroll – Ajax Load More: from n/a through 6.1.0.1.
CVE-2023-27451 1 Connekthq 1 Instant Images 2023-11-27 N/A 8.8 HIGH
Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.
CVE-2021-24334 1 Connekthq 1 Instant Images - One Click Unsplash Uploads 2021-06-11 3.5 LOW 5.4 MEDIUM
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site Scripting issue.
CVE-2021-24140 1 Connekthq 1 Ajax Load More 2021-03-22 6.5 MEDIUM 7.2 HIGH
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.