First published: Mon Oct 18 2021(Updated: )
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thimpress Learnpress | <4.1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24702 is a vulnerability in the LearnPress WordPress plugin that allows high privilege users to perform Cross-Site Scripting attacks.
CVE-2021-24702 has a severity rating of 4.8, which is considered medium.
Versions up to and exclusive of LearnPress WordPress plugin 4.1.3.1 are affected by CVE-2021-24702.
The Common Weakness Enumeration (CWE) ID for CVE-2021-24702 is 79.
To fix CVE-2021-24702, update the LearnPress WordPress plugin to version 4.1.3.1 or above.