WordPress · Ajax Load More - Filters · CVE-2026-8141
**Name of the Vulnerable Software and Affected Versions**
Ajax Load More - Filters versions prior to 3.4.2
**Description**
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting. This occurs via the `taxonomy include children` parameter, enabling the injection of arbitrary web scripts into pages that execute when accessed by a user.
**Recommendations**
Update to version 3.4.2 or later.