Description
WordPress Plugin Login With Ajax is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Login With Ajax version 3.0.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.1 or latest
References
Related Vulnerabilities
WordPress Plugin BuddyPress Multiple Security Bypass Vulnerabilities (7.2.0)
WordPress Plugin Easy2Map Cross-Site Scripting (1.5.5)
WordPress Plugin WP-Recall-Registration, Profile, Commerce & More Cross-Site Scripting (16.24.47)
MySQL Improper Validation of Array Index Vulnerability (CVE-2022-21310)
WordPress Plugin Drag and Drop Multiple File Upload-Contact Form 7 Arbitrary File Upload (1.3.3.2)