๐Ÿ” CVE Alert

CVE-2026-6495

HIGH 7.1

Ajax Load More < 7.8.4 - Reflected XSS

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
8th

The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Vendor unknown
Product ajax load more
Published May 18, 2026
Last Updated May 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ajax load more

Be the first to know when new high vulnerabilities affecting unknown ajax load more are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Ajax Load More
0 < 7.8.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c52f28c5-547d-48ae-89dd-edcdaeadcec5/

Credits

Krugov Artyom WPScan