Impact
The vulnerability is a contributor-based cross‑site scripting flaw that allows attackers to inject arbitrary JavaScript into pages rendered by the WordPress Login With Ajax plugin. When an attacker submits a malicious payload to the plugin’s Ajax handler, the script is reflected back and executed in the context of the victim’s browser, potentially enabling session hijacking or defacement. The flaw is classified under CWE‑79.
Affected Systems
This issue affects the WordPress Login With Ajax plugin, developed by Marcus (aka @msykes), on all versions 4.5.1 and earlier. Site administrators deploying these versions should verify they are running a patched release or consider disabling the plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium impact, with the vulnerability being exploitable through external actors with network access. Because the EPSS score is not published and the vulnerability is not listed in CISA’s KEV catalog, the immediate exploitation risk is uncertain, but the potential for malicious script execution in a user’s browser remains significant. Exploitation typically requires an attacker to craft a malicious Ajax request or embed a harmful payload in a shared environment that the plugin processes.
OpenCVE Enrichment