/Vulnerability Library

Ajax Load More < 7.6.1 - Unauthenticated Sensitive Information Exposure

CVE-2025-59582
Verified

Description

The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. The plugin's AJAX endpoint (wp_ajax_nopriv_alm_get_posts) allows unauthenticated users to access non-public posts (draft, private, pending, future, trash) by injecting post_status via the custom_args parameter, which bypasses the post_status authorization check in class-alm-queryargs.php.

Severity

Medium

Published Date

April 23, 2026

Template Author

pussycat0x

CVE-2025-59582.yaml
5.0Severity

CVSS Metrics

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ajax-load-more/ajax-load-more-7602-unauthenticated-sensitive-information-exposure

Remediation Steps

Update to the latest version beyond 7.6.0.2