Critical XSS Vulnerability in Ajax Load More Plugin Affects WordPress Administrators

Critical XSS Vulnerability in Ajax Load More Plugin Affects WordPress Administrators

First seen 19 May 2026, 00:16 UTC Feedlywww.incibe.escve.akaoma.cominfosec.exchange 84% similarity 64.5

Article Content

Browse articles
ThreatCluster

A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2026-6495, affects the Ajax Load More WordPress plugin prior to version 7.8.4. This flaw allows unauthenticated attackers to craft malicious URLs that execute JavaScript in the context of high-privilege users, such as administrators. The vulnerability has a CVSS score of 7.1, indicating a high severity level. Currently, there is no public proof-of-concept or evidence of exploitation. Users are advised to upgrade to version 7.8.4 or later to mitigate the risk. Temporary measures include restricting access to the plugin or disabling it until patched. The vulnerability was first published on May 18, 2026, and has been reported by multiple cybersecurity sources.

Key Points: • CVE-2026-6495 is a reflected XSS vulnerability in the Ajax Load More plugin for WordPress. • The flaw allows attackers to execute JavaScript in the browser of high-privilege users. • Users must upgrade to version 7.8.4 or later to mitigate the risk of exploitation.

ThreatCluster AI

Timeline

2026-05-18
CVE-2026-6495 published
The vulnerability affecting the Ajax Load More WordPress plugin was officially published, detailing its XSS nature.
Feedly
2026-05-19
Vulnerability reported by INCIBE-CERT
INCIBE-CERT confirmed the details of CVE-2026-6495, emphasizing its impact on high-privilege users.
www.incibe.es
2026-05-19
CVE-2026-6495 detailed by AKAOMA
AKAOMA highlighted the critical risk posed by CVE-2026-6495, urging immediate action for affected users.
cve.akaoma.com

Community

Browse all →

Tracked Entities in This Story