Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 03 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dcooney
Dcooney ajax Load More - Infinite Scroll, Load More, & Lazy Load Wordpress Wordpress wordpress |
|
| Vendors & Products |
Dcooney
Dcooney ajax Load More - Infinite Scroll, Load More, & Lazy Load Wordpress Wordpress wordpress |
Mon, 02 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 31 Jan 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1. This makes it possible for unauthenticated attackers to expose the titles and excerpts of private, draft, pending, scheduled, and trashed posts. | |
| Title | Ajax Load More – Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-02T17:57:31.920Z
Reserved: 2026-01-15T10:30:43.321Z
Link: CVE-2025-15525
Updated: 2026-02-02T17:57:28.041Z
Status : Awaiting Analysis
Published: 2026-01-31T05:16:09.820
Modified: 2026-02-03T16:44:36.630
Link: CVE-2025-15525
No data.
OpenCVE Enrichment
Updated: 2026-02-02T09:26:43Z