Skip to content
Critical XSS Vulnerability in Ajax Load More Plugin Affects WordPress Administrators

Critical XSS Vulnerability in Ajax Load More Plugin Affects WordPress Administrators

First seen 19 May 2026, 00:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 19, 2026 at 23:53 UTC
  • CVE-2026-6495 is a reflected XSS vulnerability in the Ajax Load More plugin for WordPress.
  • The flaw allows attackers to execute JavaScript in the browser of high-privilege users.
  • Users must upgrade to version 7.8.4 or later to mitigate the risk of exploitation.

A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2026-6495, affects the Ajax Load More WordPress plugin prior to version 7.8.4. This flaw allows unauthenticated attackers to craft malicious URLs that execute JavaScript in the context of high-privilege users, such as administrators. The vulnerability has a CVSS score of 7.1, indicating a high severity level. Currently, there is no public proof-of-concept or evidence of exploitation. Users are advised to upgrade to version 7.8.4 or later to mitigate the risk. Temporary measures include restricting access to the plugin or disabling it until patched. The vulnerability was first published on May 18, 2026, and has been reported by multiple cybersecurity sources.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 124d ago How this analysis works

Timeline

2026-05-18
CVE-2026-6495 published
The vulnerability affecting the Ajax Load More WordPress plugin was officially published, detailing its XSS nature.
Feedly
2026-05-19
Vulnerability reported by INCIBE-CERT
INCIBE-CERT confirmed the details of CVE-2026-6495, emphasizing its impact on high-privilege users.
www.incibe.es
2026-05-19
CVE-2026-6495 detailed by AKAOMA
AKAOMA highlighted the critical risk posed by CVE-2026-6495, urging immediate action for affected users.
cve.akaoma.com

More articles in this cluster (4)

Following this threat?

Track CVE-2026-6495 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed