cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlearn-manager learn-manager

Direction: descending
May 19, 2026

WP Learn Manager # CVE-2021-47975

CVE, Research URL

CVE-2021-47975

Application

WP Learn Manager

Date
May 16, 2026
Research Description
WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbitrary JavaScript when administrators view the field ordering interface.
Affected versions
max 1.1.2.
Status
vulnerable
Jun 10, 2024

WP Learn Manager # CVE-2021-24504

CVE, Research URL

CVE-2021-24504

Application

WP Learn Manager

Date
Aug 02, 2021
Research Description
The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)
Affected versions
max 1.1.5.
Status
vulnerable