Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-59582 PoC — WordPress Ajax Load More Plugin <= 7.6.0.2 - Sensitive Data Exposure Vulnerability

Source
Associated Vulnerability
Title:WordPress Ajax Load More Plugin <= 7.6.0.2 - Sensitive Data Exposure Vulnerability (CVE-2025-59582)
Description:Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Darren Cooney Ajax Load More ajax-load-more allows Retrieve Embedded Sensitive Data.This issue affects Ajax Load More: from n/a through <= 7.6.0.2.
Description
The Ajax Load More – Infinite Scroll plugin for WordPress is vulnerable to  Sensitive Information Exposure in all versions up to, and including, 7.6.0.2. The plugin's AJAX endpoint (wp_ajax_nopriv_alm_get_posts) allows unauthenticated  users to access non-public posts (draft, private, pending, future, trash) by
injecting post_status via the custom_args parameter, which bypasses the post_status authorization check in class-alm-queryargs.php.
File Snapshot

id: CVE-2025-59582 info: name: Ajax Load More < 7.6.1 - Unauthenticated Sensitive Information Exp ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →