Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS.

This issue affects Login With Ajax: from n/a through 4.5.1.
Published: 2026-09-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A reflected XSS vulnerability is present in the Marcus Login With Ajax WordPress plugin up to version 4.5.1. The flaw arises from insufficient input sanitization when generating web pages, allowing an attacker to inject and execute arbitrary script. This could enable credential theft, defacement, or delivery of malicious content, thereby compromising the confidentiality, integrity, and availability of the site for users who visit the affected page.

Affected Systems

The vulnerability impacts the Marcus Login With Ajax plugin. All versions from the initial release through 4.5.1 are affected; newer releases are not indicated as vulnerable.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high risk for exploiting this flaw. EPSS is not available, so exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through a crafted request to the plugin's login endpoint, as the flaw is triggered by untrusted input during page generation. Once triggered, an attacker could run scripts in the victim’s browser context.

Generated by OpenCVE AI on September 2, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Login With Ajax plugin to the latest version (4.5.2 or later) that addresses the XSS issue.
  • If an immediate update is not possible, disable or uninstall the vulnerable plugin to remove the attack surface.
  • Implement a Content Security Policy that blocks inline scripts and limits permissible script sources, mitigating the impact of any residual XSS attempts.

Generated by OpenCVE AI on September 2, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1.
Title WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-02T06:52:38.345Z

Reserved: 2026-08-31T08:39:58.675Z

Link: CVE-2026-82883

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T07:16:37.883

Modified: 2026-09-02T07:16:37.883

Link: CVE-2026-82883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T08:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')