CVE-2022-1250: LifterLMS PayPal < 1.4.0 - Reflected Cross-Site Scripting
The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-1250.
What is the title of this vulnerability?
The title of this vulnerability is 'The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue.'
What is the affected software?
The affected software is LifterLMS PayPal WordPress plugin versions up to 1.4.0.
What is the severity of this vulnerability?
The severity of this vulnerability is medium (CVSS score: 6.1).
How can I fix this vulnerability?
To fix this vulnerability, update the LifterLMS PayPal WordPress plugin to version 1.4.0 or later.