What is CVE-2026-66640?
A Stored Cross Site Scripting (XSS) vulnerability has been discovered in Login With Ajax plugin versions up to and including 4.5.1, exploitable by users with 'Contributor' level access. It is recommended to update the plugin to the latest version to mitigate the issue.
Azərbaycanca: Login With Ajax plaginin 4.5.1 və daha aşağı versiyalarında 'Contributor' səviyyəli istifadəçilər tərəfindən həyata keçirilə bilən Saxlanılmış Cross Site Scripting (XSS) zəifliyi aşkarlanıb. Təsirə məruz qalmamaq üçün plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Login With Ajax plugin are affected by CVE-2026-66640?
Login With Ajax plugin versions up to and including 4.5.1 are affected by this vulnerability.
What level of access does an attacker need to exploit the Stored XSS vulnerability in CVE-2026-66640?
This vulnerability can be exploited by users with 'Contributor' level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.