CVE-2019-15896: XSS
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The uploadimport function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulnerability that could lead to privilege escalation (administrator account creation), website redirection, and stored XSS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15896?
CVE-2019-15896 is an unauthenticated options import vulnerability in the LifterLMS plugin for WordPress.
How does CVE-2019-15896 impact LifterLMS?
CVE-2019-15896 can lead to privilege escalation, allowing an attacker to create an administrator account and potentially redirect the website.
What is the severity of CVE-2019-15896?
CVE-2019-15896 has a severity score of 9.8 (Critical).
How can I fix CVE-2019-15896?
To fix CVE-2019-15896, update your LifterLMS plugin to version 3.34.6 or later.
Where can I find more information about CVE-2019-15896?
You can find more information about CVE-2019-15896 on the Nintechnet blog, the WordPress plugin page for LifterLMS, and the WPScan Vulnerability Database.