CVE-2020-7108: XSS
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7108?
CVE-2020-7108 is a vulnerability in the LearnDash LMS plugin for WordPress that allows for cross-site scripting (XSS) attacks via the ld-profile search field.
How severe is CVE-2020-7108?
CVE-2020-7108 has a severity rating of medium, with a CVSS score of 5.4.
How does CVE-2020-7108 affect LearnDash LMS plugin for WordPress?
CVE-2020-7108 affects LearnDash LMS plugin versions before 3.1.2, allowing for XSS attacks through the ld-profile search field.
How can I fix CVE-2020-7108?
To fix CVE-2020-7108, it is recommended to update the LearnDash LMS plugin to version 3.1.2 or newer.
Where can I find more information about CVE-2020-7108?
You can find more information about CVE-2020-7108 on the following references: http://packetstormsecurity.com/files/156275/LearnDash-WordPress-LMS-3.1.2-Cross-Site-Scripting.html, https://learndash.releasenotes.io/release/uCskc-version-312, and https://wpvulndb.com/vulnerabilities/10026