CVE-2023-5558: LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting
Published Jan 16, 2024
·Updated
The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
1 affected component
thimpress Learnpress Wordpress<4.2.5.5
Event History
Jan 16, 2024
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-5558?
CVE-2023-5558 is considered a high-severity vulnerability due to its potential exploitation against high privilege users.
2
How do I fix CVE-2023-5558?
To fix CVE-2023-5558, update the LearnPress WordPress plugin to version 4.2.5.5 or later.
3
What type of vulnerability is CVE-2023-5558?
CVE-2023-5558 is a Reflected Cross-Site Scripting (XSS) vulnerability.
4
Which versions of LearnPress are affected by CVE-2023-5558?
CVE-2023-5558 affects LearnPress plugin versions before 4.2.5.5.
5
Who is at risk from CVE-2023-5558?
High privilege users, such as administrators, are at significant risk from CVE-2023-5558.