← back
CVE-2021-24504

WP LMS <= 1.1.2 - Stored Cross-Site Scripting (XSS)

EPSS 0.8%CWE-352CWE-79
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
02 Aug 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Field Titles, allowing XSS payload to be used in them. Furthermore, no CSRF and capability checks were in place, allowing such attack to be performed either via CSRF or as any user (including unauthenticated)

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →