Vulnerabilities and security researches forlearn-manager learn-manager
Direction: descendingMay 19, 2026
WP Learn Manager # CVE-2021-47975
- CVE, Research URL
- Home page URL
- Application
- Date
- May 16, 2026
- Research Description
- WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbitrary JavaScript when administrators view the field ordering interface.
- Affected versions
-
max 1.1.2.
- Status
-
vulnerable
Jun 10, 2024
WP Learn Manager # CVE-2021-24504
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 02, 2021
- Research Description
- The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)
- Affected versions
-
max 1.1.5.
- Status
-
vulnerable