CLUEVO LMS, E-Learning Platform [cluevo-lms] <= 1.13.2 (unfixed)
unknown
[en] The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.13.2. This makes it possible for unauthenticated attackers to inject arbitrary...
- Affected:
- up to 1.13.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 9, 2025
CVE-2024-11328 on NVD →
CLUEVO LMS, E-Learning Platform <= 1.13.2 - Reflected Cross-Site Scripting
medium
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.13.2. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- CVSS:
- 6.1
- Affected:
- up to 1.13.2
- Fixed in:
- 1.13.3
- Disclosed:
- Jan 8, 2025
CVE-2024-11328 on NVD →
CLUEVO LMS, E-Learning Platform [cluevo-lms] <= 1.13.2 (unfixed)
unknown
[en] The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it possible for unauthenticated attackers to delete modules v...
- Affected:
- up to 1.13.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 6, 2024
CVE-2024-11444 on NVD →
CLUEVO LMS, E-Learning Platform <= 1.13.2 - Cross-Site Request Forgery to Module Deletion
medium
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it possible for unauthenticated attackers to delete modules via a...
- CVSS:
- 4.3
- Affected:
- up to 1.13.2
- Fixed in:
- 1.13.3
- Disclosed:
- Dec 5, 2024
CVE-2024-11444 on NVD →
CLUEVO LMS, E-Learning Platform [cluevo-lms] < 1.11.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions.
- Affected:
- up to 1.11.0
- Fixed in:
- 1.11.0
- Disclosed:
- Oct 6, 2023
CVE-2023-40607 on NVD →
CLUEVO LMS, E-Learning Platform <= 1.10.0 - Cross-Site Request Forgery
medium
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.0. This is due to missing nonce validation on the save_settings() function. This makes it possible for unauthenticated attackers to modify the plugin's settings a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 1.10.0
- Fixed in:
- 1.11.0
- Disclosed:
- Aug 17, 2023
CVE-2023-40607 on NVD →
CLUEVO LMS, E-Learning Platform [cluevo-lms] < 1.8.1
unknown
[en] The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Feb 7, 2022
CVE-2021-25029 on NVD →
CLUEVO E-Learning Platform <= 1.8.0 - Authenticated Cross-Site Scripting
medium
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
The CLUEVO E-Learning Platform plugin for WordPress is vulnerable to Stor...
- CVSS:
- 4.8
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Jan 10, 2022
CVE-2021-25029 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database