Cross-Site Scripting Vulnerability in AJAX Login and Registration Modal Popup by Maxim K
CVE-2024-33918
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 May 2024
What is CVE-2024-33918?
A security flaw has been identified in the AJAX Login and Registration modal popup + inline form developed by Maxim K. This vulnerability allows for improper neutralization of input during web page generation, leading to Stored Cross-Site Scripting (XSS) attacks. An attacker could exploit this weakness by injecting malicious scripts into areas where user input is processed, potentially compromising the security of user data and enabling unauthorized actions within the application.
Affected Version(s)
AJAX Login and Registration modal popup + inline form <= 2.23