Cross-Site Scripting Vulnerability in Login With Ajax Plugin by WordPress
CVE-2012-2759

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
22 May 2012

What is CVE-2012-2759?

A cross-site scripting (XSS) vulnerability exists in the Login With Ajax plugin for WordPress, specifically within the login-with-ajax.php file. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML code by manipulating the callback parameter in the lostpassword action to wp-login.php. Unsanitized input could lead to unauthorized actions on behalf of users, increasing the potential for security breaches on affected WordPress sites.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.