← back
CVE-2021-24140CWE-89

Ajax Load More < 5.3.2 - Authenticated SQL Injection

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.2%
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
nono source reports it
Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.
Affected products
Unknown · Ajax Load More