First published: Tue Nov 23 2021(Updated: )
The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Creativemindssolutions Video Lessons Manager | <1.7.2 | |
Creativemindssolutions Video Lessons Manager Pro | <3.5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24713 is classified as a medium severity vulnerability that can lead to Cross-Site Scripting (XSS) attacks.
To fix CVE-2021-24713, update the Video Lessons Manager plugin to version 1.7.2 or later and the Video Lessons Manager Pro plugin to version 3.5.9 or later.
CVE-2021-24713 affects users of the Video Lessons Manager and Video Lessons Manager Pro WordPress plugins prior to specified versions.
CVE-2021-24713 allows high privilege users to perform Cross-Site Scripting (XSS) attacks due to improper sanitization of input values.
You can identify if you are vulnerable to CVE-2021-24713 by checking the version of the Video Lessons Manager and Video Lessons Manager Pro plugins installed on your WordPress site.