CVE-2015-10140
BaseFortify
Publication date: 2025-07-22
Last updated on: 2025-07-25
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ajax_load_more | ajax_load_more | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in the Ajax Load More plugin before version 2.8.1.2 is due to missing authorization checks in some of its AJAX actions. This flaw allows any authenticated user, including those with low privileges such as subscribers, to upload and delete arbitrary files on the system.
How can this vulnerability impact me? :
This vulnerability can have a severe impact as it allows authenticated users with limited privileges to upload and delete arbitrary files. This can lead to unauthorized modification or deletion of files, potential defacement, data loss, or even remote code execution, compromising the confidentiality, integrity, and availability of the affected system.