cleantalk
Vulnerabilities and Security Researches

LearnPress – WordPress LMS Plugin, 019b0671351af53ce3553e6834c5fd28750ae63c

Published on
Sep 08, 2020
Research Description
LearnPress &#8211; WordPress LMS Plugin for Create and Sell Online Courses [learnpress] < 3.2.7.3 LearnPress <= 3.2.7.2 - Reflected Cross-Site Scripting The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.7.2.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.2.7.3.
Status
vulnerable