CVE-2026-8141Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all versions up to, and including, 3.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-30: 3Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 306-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-8141 - Stored #XSS in #Ajax Load More - Filters (#WordPress). Unauthenticated attackers can inject arbitrary scripts via taxonomy_include_children parameter. #CVSS 7.2. #CVEAlert #infosec #redteam #blueteam #cybersecurity #developers More info: https://www.valtersit.com/cve/CVE-2026-8141/

    Post summary

    The tweet announces CVE‑2026‑8141, a stored XSS vulnerability in the WordPress Ajax Load More plugin’s filters, allowing arbitrary script injection via the taxonomy_include_children parameter, with a CVSS score of 7.2 and links for more details.

    00000454
    967 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Stored XSS in Ajax Load More - Filters taxonomy_include_children parameter (CVE-2026-8141) A stored cross-site scripting (XSS) flaw impacts the Ajax Load More - Filters plugin for WordPress, specifically via the taxonomy_include_children parameter in affected filter requests/configurations. The issue is caused by insufficient input sanitization and missing output escaping, allowing attacker-supplied content to be persisted and later rendered in the browser. Exploitation is unauthenticated: an attacker can inject malicious JavaScript that triggers when an admin or site visitor loads a page where the stored payload is displayed. Successful exploitation can lead to session hijacking, admin account takeover via stolen cookies/nonces, malicious redirects, and broader site compromise. 👉 Affected: Ajax Load More - Filters plugin <= 3.4.1 | Upgrade to 3.4.2+

    Post summary

    The text discloses a stored XSS vulnerability (CVE‑2026‑8141) in Ajax Load More – Filters that allows unauthenticated attackers to inject JavaScript via the taxonomy_include_children parameter, potentially leading to account takeover; upgrading to version 3.4.2+ resolves the issue.

    00000130
    232 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8141 Stored Cross-Site Scripting in Ajax Load More - Filters Plugin WordPress 3.4.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8141

    Post summary

    The post announces CVE-2026-8141, detailing a Stored XSS flaw in Ajax Load More – Filters Plugin for WordPress 3.4.1, with no evidence of exploitation, patches, or PoC.

    00000162
    4.1K followersView on X

Explore more