CVE-2026-82883: WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS.
This issue affects Login With Ajax: from n/a through 4.5.1.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The reported vector is network-accessible and requires no privileges, but it does require user interaction. Exploitation involves causing a user to load a crafted request that triggers reflected script execution.
Which installations are affected?
Installations using the WordPress Login With Ajax plugin are affected through version 4.5.1. The available data does not identify a fixed version or any unaffected configuration.
What is the potential impact if exploitation succeeds?
The vulnerability has low impacts to confidentiality, integrity, and availability, and its scope can extend beyond the vulnerable component. In practice, successful reflected XSS can execute attacker-controlled script in the affected user's browser context.