What is CVE-2026-15360?
This vulnerability exists in the Ajax Load More WordPress plugin before version 8.0.1. It allows unauthenticated attackers to perform a time-based blind SQL injection due to improper sanitisation and escaping of a parameter. This can lead to the extraction of sensitive data from the database. Updating the plugin to version 8.0.1 or later is strongly recommended.
Azərbaycanca: Bu boşluq Ajax Load More WordPress plaginində aşkarlanıb. Autentifikasiya olunmamış hücumçular müəyyən bir parametri düzgün təmizlənməməsi səbəbindən time-based blind SQL injection həyata keçirə bilər. Hücum nəticəsində verilənlər bazasından həssas məlumatların çıxarılması mümkündür. Plaginin 8.0.1 versiyasından əvvəlki versiyaları təsirlənir, dərhal yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which plugin was CVE-2026-15360 discovered?
In the Ajax Load More WordPress plugin.
What does this vulnerability allow an attacker to do?
It allows performing a time-based blind SQL injection that can lead to the extraction of sensitive data from the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.