CVE-2021-39348: LearnPress – WordPress LMS Plugin <= 4.1.3.1 Authenticated Stored Cross-Site Scripting
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $customprofile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.3.1. This affects multi-site installations where unfilteredhtml is disabled for administrators, and sites where unfilteredhtml is disabled. Please note that this is seperate from CVE-2021-24702.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for the LearnPress WordPress plugin vulnerability?
The vulnerability ID for the LearnPress WordPress plugin vulnerability is CVE-2021-39348.
What is the severity of CVE-2021-39348?
The severity of CVE-2021-39348 is medium with a severity value of 4.8.
What is the affected software for CVE-2021-39348?
The affected software for CVE-2021-39348 is the LearnPress WordPress plugin in versions up to and including 4.1.3.1.
How does the LearnPress WordPress plugin vulnerability occur?
The LearnPress WordPress plugin vulnerability occurs due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file.
What can attackers do with the LearnPress WordPress plugin vulnerability?
Attackers with administrative user access can inject arbitrary web scripts.