What the vulnerability does
01Description
Missing Authorization vulnerability in Marcus (aka @msykes) Login With Ajax login-with-ajax allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login With Ajax: from n/a through <= 4.1.
Explanation of Vulnerability in Simple Terms
02Summary
Login With Ajax versions 4.1 and earlier contain an authorization bypass that allows an attacker to modify data through user interaction. The vulnerability stems from missing access control checks on certain functions. An authenticated or unauthenticated user who clicks a malicious link can trigger unintended changes to site data. Update to a version newer than 4.1.
What an attacker can do
03Attacker Capabilities
Modify site data by tricking a user into clicking a malicious link.
Potential impact on your site
04Site Impact
Site data can be altered without proper authorization if users click attacker-controlled links.
Conditions required to exploit
05Prerequisites
User interaction required; attacker must trick a victim into visiting a crafted URL.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 29, 2026
Record updated