cleantalk
Vulnerabilities and Security Researches

LearnPress – WordPress LMS Plugin, 299526b8-b71c-4dee-828f-d18375a9e0ca

Published on
-
Research Description
LearnPress &#8211; WordPress LMS Plugin for Create and Sell Online Courses [learnpress] < 3.2.7.3 LearnPress &lt; 3.2.7.3 - CSRF &amp; XSS Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.
Affected versions
max 3.2.7.3.
Status
vulnerable