plugin

Cluevo Lms Vulnerabilities

8 known security issues reported for the Cluevo Lms WordPress plugin. Most recent disclosed Jan 9, 2025.

4 medium

Running Cluevo Lms on your site? Check whether your installed version is affected.

Scan your site free

CLUEVO LMS, E-Learning Platform [cluevo-lms] <= 1.13.2 (unfixed)

unknown

[en] The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.13.2. This makes it possible for unauthenticated attackers to inject arbitrary...

Affected:
up to 1.13.2
Fix:
No patched version reported
Disclosed:
Jan 9, 2025

CVE-2024-11328 on NVD →

CLUEVO LMS, E-Learning Platform <= 1.13.2 - Reflected Cross-Site Scripting

medium

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.13.2. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
6.1
Affected:
up to 1.13.2
Fixed in:
1.13.3
Disclosed:
Jan 8, 2025

CVE-2024-11328 on NVD →

CLUEVO LMS, E-Learning Platform [cluevo-lms] <= 1.13.2 (unfixed)

unknown

[en] The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it possible for unauthenticated attackers to delete modules v...

Affected:
up to 1.13.2
Fix:
No patched version reported
Disclosed:
Dec 6, 2024

CVE-2024-11444 on NVD →

CLUEVO LMS, E-Learning Platform <= 1.13.2 - Cross-Site Request Forgery to Module Deletion

medium

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it possible for unauthenticated attackers to delete modules via a...

CVSS:
4.3
Affected:
up to 1.13.2
Fixed in:
1.13.3
Disclosed:
Dec 5, 2024

CVE-2024-11444 on NVD →

CLUEVO LMS, E-Learning Platform [cluevo-lms] < 1.11.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions.

Affected:
up to 1.11.0
Fixed in:
1.11.0
Disclosed:
Oct 6, 2023

CVE-2023-40607 on NVD →

CLUEVO LMS, E-Learning Platform <= 1.10.0 - Cross-Site Request Forgery

medium

The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.0. This is due to missing nonce validation on the save_settings() function. This makes it possible for unauthenticated attackers to modify the plugin's settings a forged request gr...

CVSS:
4.3
Affected:
up to 1.10.0
Fixed in:
1.11.0
Disclosed:
Aug 17, 2023

CVE-2023-40607 on NVD →

CLUEVO LMS, E-Learning Platform [cluevo-lms] < 1.8.1

unknown

[en] The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Feb 7, 2022

CVE-2021-25029 on NVD →

CLUEVO E-Learning Platform <= 1.8.0 - Authenticated Cross-Site Scripting

medium

The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed The CLUEVO E-Learning Platform plugin for WordPress is vulnerable to Stor...

CVSS:
4.8
Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Jan 10, 2022

CVE-2021-25029 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database