CVE-2023-50875: WordPress Sensei LMS Plugin <= 4.17.0 is vulnerable to Cross Site Scripting (XSS)
Published Feb 12, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes, & Learning allows Stored XSS.This issue affects Sensei LMS – Online Courses, Quizzes, & Learning: from n/a through 4.17.0.
Affected Software
1 affected component
Automattic Sensei Lms Wordpress<=4.17.0
Remediation
Information
Update to 4.18.0 or a higher version.
Event History
Feb 12, 2024
CVE Published
via MITRE·06:50 AM
Data Sourced
via MITRE·06:50 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50875?
CVE-2023-50875 has a high severity rating due to its potential for Stored Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2023-50875?
To mitigate CVE-2023-50875, update Automattic Sensei LMS to version 4.17.1 or later.
3
What software is affected by CVE-2023-50875?
CVE-2023-50875 affects Automattic Sensei LMS versions up to 4.17.0.
4
What type of vulnerability is CVE-2023-50875?
CVE-2023-50875 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2023-50875 be exploited by an attacker?
Yes, an attacker can exploit CVE-2023-50875 to inject malicious scripts into web pages viewed by other users.