Skip to content
CVE-2026-6495 - Exploits & Severity

CVE-2026-6495 - Exploits & Severity

Feedly May 18, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)

The Ajax Load More WordPress plugin before version 7.8.4 does not properly sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting vulnerability.

An unauthenticated attacker can craft a malicious URL containing JavaScript code that, when clicked by a high-privilege user such as an administrator, will execute arbitrary JavaScript in the context of that user's browser session, potentially allowing the attacker to impersonate the administrator and perform unauthorized actions.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patch available - upgrade Ajax Load More WordPress plugin to version 7.8.4 or later.

Immediately upgrade the Ajax Load More plugin to version 7.8.4 or later. As a temporary measure, restrict access to the affected plugin functionality or disable the plugin until it can be patched. Additionally, educate administrators and high-privilege users to avoid clicking untrusted links.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Feedly found the first article mentioning CVE-2026-6495 . See article

NVD published the first details for CVE-2026-6495

GitHub Advisories released a security advisory .

A CVSS base score of 7.1 has been assigned.

[GHSA-35c5-rhm2-6w7w] The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a

Update Mon May 18 11:32:50 UTC 2026

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities