PT-2026-41461 · Wplearnmanager · Wp Learn Manager

Mohammed Adam

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2021-47975

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm fieldordering page with XSS payloads in the fieldtitle field to execute arbitrary JavaScript when administrators view the field ordering interface.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47975

Affected Products

Wp Learn Manager