Namaste! LMS <= 2.6.5 - Cross-Site Request Forgery
medium
The Namaste! LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administ...
- CVSS:
- 4.3
- Affected:
- up to 2.6.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 24, 2025
CVE-2025-27353 on NVD →
Namaste! LMS [namaste-lms] <= 2.6.5 (unfixed + closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS allows Cross Site Request Forgery. This issue affects Namaste! LMS: from n/a through 2.6.5.
- Affected:
- up to 2.6.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 24, 2025
CVE-2025-27353 on NVD →
Namaste! LMS [namaste-lms] < 2.6.5 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Namaste! LMS allows Cross Site Request Forgery.This issue affects Namaste! LMS: from n/a through 2.6.4.1.
- Affected:
- up to 2.6.5
- Fixed in:
- 2.6.5
- Disclosed:
- Dec 6, 2024
CVE-2024-53809 on NVD →
Namaste! LMS <= 2.6.4.1 - Cross-Site Request Forgery
medium
The Namaste! LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.4.1. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site ad...
- CVSS:
- 4.3
- Affected:
- up to 2.6.4.1
- Fixed in:
- 2.6.5
- Disclosed:
- Dec 2, 2024
CVE-2024-53809 on NVD →
Namaste! LMS [namaste-lms] < 2.6.3 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Reflected XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Oct 29, 2024
CVE-2024-50407 on NVD →
Namaste! LMS [namaste-lms] < 2.6.4.1 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.4.
- Affected:
- up to 2.6.4.1
- Fixed in:
- 2.6.4.1
- Disclosed:
- Oct 29, 2024
CVE-2024-50410 on NVD →
Namaste! LMS [namaste-lms] < 2.6.3 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Oct 29, 2024
CVE-2024-50409 on NVD →
Namaste! LMS [namaste-lms] < 2.6.4 (closed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Kiboko Labs Namaste! LMS allows Object Injection.This issue affects Namaste! LMS: from n/a through 2.6.3.
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.4
- Disclosed:
- Oct 28, 2024
CVE-2024-50408 on NVD →
Namaste! LMS <= 2.6.3 - Authenticated (Subscriber+) PHP Object Injection
high
The Namaste! LMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.6.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 8.8
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.4
- Disclosed:
- Oct 24, 2024
CVE-2024-50408 on NVD →
Namaste! LMS <= 2.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 2.6.4
- Fixed in:
- 2.6.4.1
- Disclosed:
- Oct 24, 2024
CVE-2024-50410 on NVD →
Namaste! LMS <= 2.6.2 - Authenticated (Student+) Stored Cross-Site Scripting
medium
The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with student-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Oct 24, 2024
CVE-2024-50409 on NVD →
Namaste! LMS <= 2.6.2 - Reflected Cross-Site Scripting
medium
The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Oct 24, 2024
CVE-2024-50407 on NVD →
Namaste! LMS [namaste-lms] < 2.6.1.2 (closed)
unknown
[en] The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 2.6.1.2
- Fixed in:
- 2.6.1.2
- Disclosed:
- Nov 15, 2023
CVE-2023-4602 on NVD →
Namaste! LMS <= 2.6.1.1 - Reflected Cross-Site Scripting
medium
The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 2.6.1.1
- Fixed in:
- 2.6.1.2
- Disclosed:
- Nov 14, 2023
CVE-2023-4602 on NVD →
Namaste! LMS [namaste-lms] < 2.5.9.2 (closed)
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Namaste! LMS plugin <= 2.5.9.1 versions.
- Affected:
- up to 2.5.9.2
- Fixed in:
- 2.5.9.2
- Disclosed:
- Apr 6, 2023
CVE-2023-24383 on NVD →
Namaste! LMS [namaste-lms] < 2.6 (closed)
unknown
[en] The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 2.6
- Fixed in:
- 2.6
- Disclosed:
- Mar 13, 2023
CVE-2023-0844 on NVD →
Namaste! LMS <= 2.5.9.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'accept_other_payment_methods', 'other_payment_methods' Parameters
medium
The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accept_other_payment_methods', 'other_payment_methods' parameters in versions up to 2.5.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level...
- CVSS:
- 4.4
- Affected:
- up to 2.5.9.9
- Fixed in:
- 2.6
- Disclosed:
- Mar 3, 2023
CVE-2023-0844 on NVD →
Namaste! LMS [namaste-lms] < 2.5.9.4 (closed)
unknown
[en] The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 2.5.9.4
- Fixed in:
- 2.5.9.4
- Disclosed:
- Feb 27, 2023
CVE-2023-0548 on NVD →
Namaste! LMS <= 2.5.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Namaste! LMS for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.5.9.3 due to insufficient input sanitization and output escaping on the currency setting value. This makes it possible for authenticated attackers, with administrative-level permissions an...
- CVSS:
- 4.4
- Affected:
- up to 2.5.9.3
- Fixed in:
- 2.5.9.4
- Disclosed:
- Jan 31, 2023
CVE-2023-0548 on NVD →
Namaste! LMS <= 2.5.9.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Certificate Title value in versions up to, and including, 2.5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...
- CVSS:
- 4.4
- Affected:
- up to 2.5.9.2
- Fixed in:
- 2.5.9.2
- Disclosed:
- Jan 27, 2023
CVE-2023-24383 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database