WordPress Wp Login with Ajax plugin <= 0.6 - CSRF to Stored Cross-Site Scripting vulnerability
CVE-2024-54416
7.1HIGH
What is CVE-2024-54416?
A vulnerability has been identified in the Wp Login with Ajax plugin developed by Navdeep Kumar, which presents a Cross-Site Request Forgery (CSRF) flaw that can lead to Stored Cross-Site Scripting (XSS) attacks. The issue is present in all versions up to 0.6, enabling attackers to potentially execute malicious scripts in the context of an authenticated user's session. This vulnerability poses a significant security risk, as it may lead to unauthorized actions being executed on behalf of legitimate users.
Affected Version(s)
Wp Login with Ajax 0 <= 0.6