5.4
CVSSv3

CVE-2021-24308

Published: 24/05/2021 Updated: 03/06/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin prior to 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lifterlms lifterlms

Exploits

WordPress LifterLMS plugin version 4210 suffers from a persistent cross site scripting vulnerability ...