CVE-2024-13599: LearnPress – WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping of a lesson name. This makes it possible for authenticated attackers, with LP Instructor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13599?
CVE-2024-13599 is considered a medium severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13599?
To fix CVE-2024-13599, update the LearnPress – WordPress LMS Plugin to the latest version, 4.2.7.6 or above.
Who is affected by CVE-2024-13599?
CVE-2024-13599 affects all versions of the LearnPress - WordPress LMS Plugin up to and including 4.2.7.5.
What type of vulnerability is CVE-2024-13599?
CVE-2024-13599 is a Stored Cross-Site Scripting vulnerability caused by insufficient input sanitization.
Can CVE-2024-13599 be exploited remotely?
Yes, CVE-2024-13599 can be exploited remotely by authenticated attackers.