ZeroHour

CVE-2026-82883

moderate

Reflected XSS in WordPress Login With Ajax plugin (through 4.5.1)

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

The Login With Ajax WordPress plugin by Marcus fails to properly neutralize input during web page generation, allowing reflected cross-site scripting (CWE-79). An attacker would trigger the flaw by luring a logged-in or browsing user to a crafted link or submission that passes malicious input through the plugin's rendering logic, which is then executed in the victim's browser without requiring any privileges. Successful exploitation could let the attacker execute arbitrary script in the victim's session, enabling cookie theft, redirection, or unauthorized actions in the context of the affected WordPress site. Any WordPress site running Login With Ajax version 4.5.1 or earlier is affected. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts exploitation probability in the next 30 days at roughly 0.1%.

What to do: Site administrators should update the Login With Ajax plugin to the latest patched release as soon as one is available (anything newer than 4.5.1). Until updating, verify the installed plugin version in the WordPress admin dashboard, avoid clicking untrusted links pointing to affected sites while logged in, and consider temporarily deactivating the plugin if the site does not rely on its Ajax login functionality.

Affected
Marcus Login With Ajax (WordPress plugin)all versions through 4.5.1 (n/a to 4.5.1 inclusive)
Estimated exposure
moderatetens of thousands of WordPress sites (≈30,000–40,000 installs based on the plugin's active-install count) — The Login With Ajax plugin's publicly listed active-install count on wordpress.org is in the tens of thousands, and only installs running version 4.5.1 or earlier are affected, with actual exploitability further reduced because reflected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.