CVE-2024-56939: XSS
Published Feb 12, 2025
·Updated
LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class.
Affected Software
2 affected components
LearnDash LearnDash
LearnDash LearnDash Wordpress=6.7.1
Event History
Feb 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-56939?
CVE-2024-56939 is classified as a stored cross-site scripting (XSS) vulnerability, which can have serious implications for website security.
2
How do I fix CVE-2024-56939?
To fix CVE-2024-56939, update LearnDash to the latest version that addresses this vulnerability.
3
What versions of LearnDash are affected by CVE-2024-56939?
CVE-2024-56939 specifically affects LearnDash version 6.7.1.
4
How can CVE-2024-56939 impact my website?
CVE-2024-56939 can allow attackers to execute malicious scripts in the context of a user's session, potentially leading to data theft or account compromise.
5
Is CVE-2024-56939 a local or remote vulnerability?
CVE-2024-56939 is a remote vulnerability, allowing attackers to exploit the XSS flaw from any location with internet access.