Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS.

This issue affects Login With Ajax: from n/a through 4.5.1.
Published: 2026-09-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Update
AI Analysis

Impact

A reflected XSS vulnerability is present in the Marcus Login With Ajax WordPress plugin up to version 4.5.1. The flaw arises from insufficient input sanitization when generating web pages, allowing an attacker to inject and execute arbitrary script. This could enable credential theft, defacement, or delivery of malicious content, thereby compromising the confidentiality, integrity, and availability of the site for users who visit the affected page.

Affected Systems

The vulnerability impacts the Marcus Login With Ajax plugin. All versions from the initial release through 4.5.1 are affected; newer releases are not indicated as vulnerable.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high risk for exploiting this flaw. EPSS is not available, so exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through a crafted request to the plugin's login endpoint, as the flaw is triggered by untrusted input during page generation. Once triggered, an attacker could run scripts in the victim’s browser context.

Generated by OpenCVE AI on September 2, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Login With Ajax plugin to the latest version (4.5.2 or later) that addresses the XSS issue.
  • If an immediate update is not possible, disable or uninstall the vulnerable plugin to remove the attack surface.
  • Implement a Content Security Policy that blocks inline scripts and limits permissible script sources, mitigating the impact of any residual XSS attempts.

Generated by OpenCVE AI on September 2, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Marcus
Marcus login With Ajax
Wordpress
Wordpress wordpress
Vendors & Products Marcus
Marcus login With Ajax
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1.
Title WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Marcus Login With Ajax
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T13:49:13.696Z

Reserved: 2026-08-31T08:39:58.675Z

Link: CVE-2026-82883

cve-icon Vulnrichment

Updated: 2026-09-03T13:48:23.883Z

cve-icon NVD

Status : Deferred

Published: 2026-09-02T07:16:37.883

Modified: 2026-09-03T14:17:02.593

Link: CVE-2026-82883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T16:42:29Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')