CVE-2024-4971: LearnPress – WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.2.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4971?
CVE-2024-4971 is classified as a medium-severity vulnerability due to its ability to allow reflected cross-site scripting.
How do I fix CVE-2024-4971?
To fix CVE-2024-4971, update the LearnPress – WordPress LMS Plugin to version 4.2.6.7 or later.
What does CVE-2024-4971 affect?
CVE-2024-4971 affects all versions of the LearnPress – WordPress LMS Plugin up to and including 4.2.6.6.
Who is impacted by CVE-2024-4971?
CVE-2024-4971 can impact any website using the vulnerable versions of the LearnPress plugin, especially affecting unauthenticated users.
What type of vulnerability is CVE-2024-4971?
CVE-2024-4971 is a reflected cross-site scripting (XSS) vulnerability caused by insufficient input sanitization.