CVE-2026-15295

Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.


We have discovered 1,218 live websites that are affected by CVE-2026-15295.

Run a Free Instant Scan




Affected Software

Product  Ajax Load More
Category Wordpress Plugins
Vulnerable Domains1,218 live websites (23% of Ajax Load More install base)
Vulnerable Versions
  • from 0 through 7.0.1
Vulnerable Versions Count79 versions ( 71% of all versions)


Common Weakness Enumeration

CWE-692 Incomplete Denylist to Cross-Site Scripting



Details

  • Published - Jul 10, 2026
  • Updated - Jul 14, 2026

Credits

  • afei (finder)

Website Distribution by Country

Number of websites using CVE-2026-15295
United States417 websites



Russia87 websites
Germany68 websites
Japan67 websites
GB65 websites
France42 websites
Canada32 websites
Brazil32 websites
Poland29 websites
Australia28 websites

Website Distribution by TLD

Number of websites using CVE-2026-15295
.com541 websites
.ru63 websites
.org43 websites
.co.uk35 websites
.de34 websites
.com.br31 websites
.com.au29 websites
.net28 websites
.jp22 websites
.pl21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15295

Top websites that are affected by CVE-2026-15295. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
************.com United States*,***
**************.***.au United States**,***
***.moe Japan**,***
********.com United States**,***
************.***.au United States**,***
****************.com United States**,***
****.************.com United States***,***
*******************.com United States***,***
*********.net United States***,***
See full domain list

FAQ

CVE-2026-15295 is Incomplete Denylist to Cross-Site Scripting in Ajax Load More
A total of 1,218 websites have been identified as vulnerable to CVE-2026-15295, based on global website indexing conducted by WebTechSurvey.
The Ajax Load More is affected by the CVE-2026-15295 vulnerability.
Ajax Load More versions up to and including 7.0.1 are vulnerable to CVE-2026-15295.