Where
-Infinity
0
Severity
6.1
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgmcoderedeem POST Parameter in user-code-redemption.php, the ulgmuserfirst POST Parameter in user-registration-form.php, the ulgmuserlast POST Parameter in user-registration-form.php, the ulgmuseremail POST Parameter in user-registration-form.php, the ulgmcoderegistration POST Parameter in user-registration-form.php, the ulgmtermsconditions POST Parameter in user-registration-form.php, the ulgmtotalseats POST Parameter in frontend-uogroupsbuycourses.php, the uncannygroupsignupuserfirst POST Parameter in group-registration-form.php, the uncannygroupsignupuserlast POST Parameter in group-registration-form.php, the uncannygroupsignupuserlogin POST Parameter in group-registration-form.php, the uncannygroupsignupuseremail POST Parameter in group-registration-form.php, the success-invited GET Parameter in frontend-uogroups.php, the bulk-errors GET Parameter in frontend-uogroups.php, or the message GET Parameter in frontend-uogroups.php.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203