The WordPress Infinite Scroll – Ajax Load More plugin for...
Moderate severity
Unreviewed
Published
Sep 7, 2022
to the GitHub Advisory Database
•
Updated Jul 29, 2023
Description
Published by the National Vulnerability Database
Sep 6, 2022
Published to the GitHub Advisory Database
Sep 7, 2022
Last updated
Jul 29, 2023
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions up to, and including, 5.5.3 due to insufficient file path validation on the alm_repeaters_export() function. This makes it possible for authenticated attackers, with administrative privileges, to download arbitrary files hosted on the server that may contain sensitive content, such as the wp-config.php file.
References