Executive brief
Login With Ajax is a WordPress plugin that enables user authentication via external login systems. The plugin contains a reflected cross-site scripting (XSS) flaw that allows attackers to inject malicious scripts into web pages viewed by site administrators or users. Successful exploitation could lead to account compromise, credential theft, or malware distribution to site visitors.
Technical details
A reflected XSS vulnerability in Marcus Login With Ajax (versions up to 4.5.1) stems from improper neutralization of user-supplied input during web page generation. The vulnerability allows an attacker to craft a malicious URL containing JavaScript code that executes in the browser of any user who clicks the link. User interaction is required—the victim must visit a crafted page or click a malicious link. An attacker can steal session cookies, hijack admin accounts, or execute arbitrary actions on behalf of the victim. No official patch has been released as of the published date; Patchstack has provided a mitigation rule to block exploitation attempts.
Affected products
- Marcus Login With Ajax through 4.5.1
Timeline
- 2026-09-02: disclosed: CVE-2026-82883 published
- 2026-07-26: other: Vulnerability reported to Patchstack by Adam Kahlon