PoC Index

CVE-2015-10140

HIGH 8.8EPSS 1.0%

The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.01% chance of exploitation in the next 30 days, 61th percentile
Published
2025-07-22
Updated
2026-01-09

Proof-of-concept exploits (1)

Metasploit modules (1)

References

Related