CVE-2022-2945
06.09.2022, 18:15
The WordPress Infinite Scroll Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.
Vendor | Product | Version |
---|---|---|
connekthq | ajax_load_more | 𝑥 ≤ 5.5.3 |
𝑥
= Vulnerable software versions
References