wp-plugin/ajax-load-more is vulnerable to SQL Injection
91
Critical Risk
The custom_args parameter is concatenated into a SQL query without sanitization or escaping. An unauthenticated attacker can send a crafted request that performs time-based blind SQL injection and extract sensitive data from the database. The fix sanitizes and escapes custom_args before it is used in the query.
You are affected if you are using a version that falls within the vulnerable range.
wp-plugin/ajax-load-more is vulnerable to SQL Injection in versions 2.6.3 - 8.0.0.
Upgrade the wp-plugin/ajax-load-more and/or the Ajax Load More library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.