Junglewise Threat Intelligence

CVE-2026-66640: Login With Ajax Cross Site Scripting (XSS) in Contributor Role

CVE-2026-66640 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Executive brief

Login With Ajax is a WordPress plugin that enables user authentication via external services. Versions 4.5.1 and earlier contain a Cross Site Scripting (XSS) vulnerability accessible to users with the Contributor role. An attacker with contributor privileges could inject malicious scripts that steal visitor data or hijack user accounts, requiring a privileged user to interact with a crafted link or page.

Technical details

The vulnerability is a Stored Cross Site Scripting (XSS) flaw in Login With Ajax plugin <= 4.5.1, exploitable by authenticated users with Contributor role privileges. The vulnerability exists in an unspecified component and requires user interaction (such as clicking a malicious link) to be successfully exploited. An attacker can inject malicious JavaScript that executes in the browser context of other visitors or administrators, potentially leading to session hijacking, credential theft, or malware distribution. No official patch has been released; remediation requires updating to a patched version or disabling the plugin.

Affected products

  • Login With Ajax Login With Ajax <= 4.5.1

Timeline

  • 2026-07-09: disclosed: Reported by Ananda Dhakal (Patchstack)
  • 2026-08-18: advisory: Published by Patchstack

References