Impact
A reflected XSS vulnerability is present in the Marcus Login With Ajax WordPress plugin up to version 4.5.1. The flaw arises from insufficient input sanitization when generating web pages, allowing an attacker to inject and execute arbitrary script. This could enable credential theft, defacement, or delivery of malicious content, thereby compromising the confidentiality, integrity, and availability of the site for users who visit the affected page.
Affected Systems
The vulnerability impacts the Marcus Login With Ajax plugin. All versions from the initial release through 4.5.1 are affected; newer releases are not indicated as vulnerable.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high risk for exploiting this flaw. EPSS is not available, so exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through a crafted request to the plugin's login endpoint, as the flaw is triggered by untrusted input during page generation. Once triggered, an attacker could run scripts in the victim’s browser context.
OpenCVE Enrichment