CVE-2022-0271: LearnPress < 4.1.6 - Reflected Cross-Site Scripting
Published Apr 11, 2022
·Updated
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lpbackgroundsingleemail AJAX action, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
thimpress Learnpress Wordpress<4.1.6
Event History
Apr 11, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-0271.
2
What is the severity of CVE-2022-0271?
The severity of CVE-2022-0271 is medium with a severity value of 6.1.
3
What is the affected software of CVE-2022-0271?
The affected software of CVE-2022-0271 is the LearnPress WordPress plugin version up to and excluding 4.1.6.
4
What is the CWE of CVE-2022-0271?
The CWE of CVE-2022-0271 is CWE-79.
5
How can I fix CVE-2022-0271?
To fix CVE-2022-0271, update the LearnPress WordPress plugin to version 4.1.6 or later.