PT-2021-16026 · WordPress · Wplms
Mohammed Adam
·
Published
2021-08-02
·
Updated
2022-11-09
·
CVE-2021-24504
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The WP LMS – Best WordPress LMS Plugin versions 1.1.2 and earlier
Description
The issue arises from the plugin's failure to properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Additionally, the lack of CSRF and capability checks enables such attacks to be performed either via CSRF or as any user, including unauthenticated ones.
Recommendations
For versions 1.1.2 and earlier, update to a version that properly sanitizes and validates User Field Titles and implements CSRF and capability checks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wplms