Cross-site Scripting (XSS) Vulnerability in LearnPress Export Import
CVE-2024-32588

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 April 2024

What is CVE-2024-32588?

A vulnerability exists in the ThimPress LearnPress Export Import Plugin due to improper neutralization of user input during web page generation, leading to potential Cross-site Scripting (XSS) attacks. This issue affects all versions up to 4.0.3, allowing attackers to execute arbitrary scripts in the context of a user's browser session. Attackers can exploit this vulnerability by injecting malicious code into web pages viewed by unsuspecting users, compromising sensitive information and user accounts. Website administrators using the affected plugin should take immediate action to mitigate this risk.

Affected Version(s)

LearnPress Export Import <= 4.0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.
The Cyber Security Vulnerability Database.