First published: Mon Apr 11 2022(Updated: )
The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it back via the lp_background_single_email AJAX action, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thimpress Learnpress | <4.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-0271.
The severity of CVE-2022-0271 is medium with a severity value of 6.1.
The affected software of CVE-2022-0271 is the LearnPress WordPress plugin version up to and excluding 4.1.6.
The CWE of CVE-2022-0271 is CWE-79.
To fix CVE-2022-0271, update the LearnPress WordPress plugin to version 4.1.6 or later.