← back
CVE-2022-2945mediumCWE-22

WordPress Infinite Scroll – Ajax Load More <= 5.5.3 - Directory Traversal

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.9epss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.5.3 via the 'type' parameter found in the alm_get_layout() function. This makes it possible for authenticated attackers, with administrative permissions, to read the contents of arbitrary files on the server, which can contain sensitive information.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N