cve.akaoma.com Critical XSS Vulnerability in Ajax Load More Plugin Affects WordPress Administrators
Article Content
- •CVE-2026-6495 is a reflected XSS vulnerability in the Ajax Load More plugin for WordPress.
- •The flaw allows attackers to execute JavaScript in the browser of high-privilege users.
- •Users must upgrade to version 7.8.4 or later to mitigate the risk of exploitation.
A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2026-6495, affects the Ajax Load More WordPress plugin prior to version 7.8.4. This flaw allows unauthenticated attackers to craft malicious URLs that execute JavaScript in the context of high-privilege users, such as administrators. The vulnerability has a CVSS score of 7.1, indicating a high severity level. Currently, there is no public proof-of-concept or evidence of exploitation. Users are advised to upgrade to version 7.8.4 or later to mitigate the risk. Temporary measures include restricting access to the plugin or disabling it until patched. The vulnerability was first published on May 18, 2026, and has been reported by multiple cybersecurity sources.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-6495 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…