CVE-2026-66640: WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
Affected Software
1 affected component
WordPress Login With Ajax<=4.5.1
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected and who can exploit the issue?
Sites using WordPress Login With Ajax version 4.5.1 or earlier are in scope. Exploitation requires an attacker to have Contributor-level access.
2
What conditions are required for exploitation and what is the potential impact?
The CVSS vector indicates network reachability, low attack complexity, required low privileges, and required user interaction. Successful exploitation can affect confidentiality, integrity, and availability beyond the initially impacted security authority.