The WordPress Infinite Scroll – Ajax Load More plugin for...
Low severity
Unreviewed
Published
Sep 7, 2022
to the GitHub Advisory Database
•
Updated Jan 11, 2024
Description
Published by the National Vulnerability Database
Sep 6, 2022
Published to the GitHub Advisory Database
Sep 7, 2022
Last updated
Jan 11, 2024
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.
References