CVE-2021-24702: LearnPress < 4.1.3.1 - Multiple Admin+ Stored Cross-Site Scripting
Published Oct 18, 2021
·Updated
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltredhtml capability is disallowed
Affected Software
1 affected component
thimpress Learnpress Wordpress<4.1.3.1
Event History
Oct 18, 2021
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-24702?
CVE-2021-24702 is a vulnerability in the LearnPress WordPress plugin that allows high privilege users to perform Cross-Site Scripting attacks.
2
How severe is CVE-2021-24702?
CVE-2021-24702 has a severity rating of 4.8, which is considered medium.
3
Which software versions are affected by CVE-2021-24702?
Versions up to and exclusive of LearnPress WordPress plugin 4.1.3.1 are affected by CVE-2021-24702.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-24702?
The Common Weakness Enumeration (CWE) ID for CVE-2021-24702 is 79.
5
How can CVE-2021-24702 be fixed?
To fix CVE-2021-24702, update the LearnPress WordPress plugin to version 4.1.3.1 or above.