Skip to content

CVE-2026-6495

CVE

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
May 18, 2026
Last Seen
May 19, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A reflected cross-site scripting (XSS) vulnerability, identified as CVE-2026-6495, affects the Ajax Load More WordPress plugin prior to version 7.8.4. This flaw allows unauthenticated attackers to craft malicious URLs that execute JavaScript in the context of high-privilege users, such as administra...

Public Exploits

Checking GitHub for proof-of-concept code…