The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 1,218 live websites that are affected by CVE-2026-15295.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,218 live websites (23% of Ajax Load More install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 79 versions ( 71% of all versions) |
| 417 websites | |
| 87 websites | |
| 68 websites | |
| 67 websites | |
| 65 websites | |
| 42 websites | |
| 32 websites | |
| 32 websites | |
| 29 websites | |
| 28 websites |
| .com | 541 websites |
| .ru | 63 websites |
| .org | 43 websites |
| .co.uk | 35 websites |
| .de | 34 websites |
| .com.br | 31 websites |
| .com.au | 29 websites |
| .net | 28 websites |
| .jp | 22 websites |
| .pl | 21 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | *,*** | ||
| ************.com | *,*** | ||
| **************.***.au | **,*** | ||
| ***.moe | **,*** | ||
| ********.com | **,*** | ||
| ************.***.au | **,*** | ||
| ****************.com | **,*** | ||
| ****.************.com | ***,*** | ||
| *******************.com | ***,*** | ||
| *********.net | ***,*** |
FAQ