Beveiligingsadvies

CVE-2015-10140

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-07-22 13:20:59
Laatst bijgewerkt 2026-01-09 20:22:04
Toegewezen door WPScan
CVSS-score 8.8
Status PUBLISHED

Beschrijving

The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.