Impact
Cross‑Site Request Forgery in the Ultimate AJAX Login plugin allows an attacker to submit authenticated requests on behalf of a logged‑in user. The flaw also permits reflected cross‑site scripting, enabling injection of malicious scripts into the response. An attacker could hijack the user session, modify site settings, or exfiltrate sensitive data. This weakness is classified as CWE‑352, reflecting the vulnerability in request validation.
Affected Systems
The vulnerability is present in Samer Bechara’s Ultimate AJAX Login WordPress plugin for all releases from earliest versions through 1.2.1. WordPress site owners who have not upgraded past version 1.2.1 are exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, although the EPSS score of less than 1% suggests exploitation is currently rare. The flaw is not listed in CISA’s KEV catalog, so no widespread exploitation campaigns are reported. An attacker could trigger the CSRF by convincing a logged‑in user to click a crafted link or load a malicious page that submits the vulnerable request, potentially leading to unauthorized actions or XSS payload delivery.
OpenCVE Enrichment
EUVD