Executive brief
Login With Ajax is a WordPress plugin that enables user authentication via external services. Versions 4.5.1 and earlier contain a Cross Site Scripting (XSS) vulnerability accessible to users with the Contributor role. An attacker with contributor privileges could inject malicious scripts that steal visitor data or hijack user accounts, requiring a privileged user to interact with a crafted link or page.
Technical details
The vulnerability is a Stored Cross Site Scripting (XSS) flaw in Login With Ajax plugin <= 4.5.1, exploitable by authenticated users with Contributor role privileges. The vulnerability exists in an unspecified component and requires user interaction (such as clicking a malicious link) to be successfully exploited. An attacker can inject malicious JavaScript that executes in the browser context of other visitors or administrators, potentially leading to session hijacking, credential theft, or malware distribution. No official patch has been released; remediation requires updating to a patched version or disabling the plugin.
Affected products
- Login With Ajax Login With Ajax <= 4.5.1
Timeline
- 2026-07-09: disclosed: Reported by Ananda Dhakal (Patchstack)
- 2026-08-18: advisory: Published by Patchstack