Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Darren Cooney | Ajax Load More | 0 ~ 7.6.0.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. The plugin's AJAX endpoint (wp_ajax_nopriv_alm_get_posts) allows unauthenticated users to access non-public posts (draft, private, pending, future, trash) by injecting post_status via the custom_args parameter, which bypasses the post_status authorization check in class-alm-queryargs.php. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-59582.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet