Unauthenticated Reflected Cross-Site Scripting Vulnerability in LearnPress Export Import
CVE-2024-9609
6.1MEDIUM
Key Information:
- Vendor
- Thimpress
- Status
- Learnpress Export Import – WordPress Extension For Learnpress
- Vendor
- CVE Published:
- 15 November 2024
Summary
The LearnPress Export Import extension for the LearnPress plugin in WordPress is susceptible to Reflected Cross-Site Scripting due to lacking proper input sanitization and output escaping on the 'learnpress_import_form_server' parameter. This flaw affects all versions up to and including 4.0.4, allowing unauthenticated attackers to execute arbitrary web scripts within user sessions. Successful exploitation occurs when an attacker convinces a user to click on a malicious link, leading to unauthorized actions and potential data compromise within the affected web applications.
Affected Version(s)
LearnPress Export Import – WordPress extension for LearnPress * <= 4.0.4
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Dale Mavers