plugin

Namaste Lms Vulnerabilities

20 known security issues reported for the Namaste Lms WordPress plugin. Most recent disclosed Feb 24, 2025.

1 high 9 medium

Running Namaste Lms on your site? Check whether your installed version is affected.

Scan your site free

Namaste! LMS <= 2.6.5 - Cross-Site Request Forgery

medium

The Namaste! LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administ...

CVSS:
4.3
Affected:
up to 2.6.5
Fix:
No patched version reported
Disclosed:
Feb 24, 2025

CVE-2025-27353 on NVD →

Namaste! LMS [namaste-lms] <= 2.6.5 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS allows Cross Site Request Forgery. This issue affects Namaste! LMS: from n/a through 2.6.5.

Affected:
up to 2.6.5
Fix:
No patched version reported
Disclosed:
Feb 24, 2025

CVE-2025-27353 on NVD →

Namaste! LMS [namaste-lms] < 2.6.5 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Namaste! LMS allows Cross Site Request Forgery.This issue affects Namaste! LMS: from n/a through 2.6.4.1.

Affected:
up to 2.6.5
Fixed in:
2.6.5
Disclosed:
Dec 6, 2024

CVE-2024-53809 on NVD →

Namaste! LMS <= 2.6.4.1 - Cross-Site Request Forgery

medium

The Namaste! LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.4.1. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site ad...

CVSS:
4.3
Affected:
up to 2.6.4.1
Fixed in:
2.6.5
Disclosed:
Dec 2, 2024

CVE-2024-53809 on NVD →

Namaste! LMS [namaste-lms] < 2.6.3 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Reflected XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Oct 29, 2024

CVE-2024-50407 on NVD →

Namaste! LMS [namaste-lms] < 2.6.4.1 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.4.

Affected:
up to 2.6.4.1
Fixed in:
2.6.4.1
Disclosed:
Oct 29, 2024

CVE-2024-50410 on NVD →

Namaste! LMS [namaste-lms] < 2.6.3 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kiboko Labs Namaste! LMS allows Stored XSS.This issue affects Namaste! LMS: from n/a through 2.6.2.

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Oct 29, 2024

CVE-2024-50409 on NVD →

Namaste! LMS [namaste-lms] < 2.6.4 (closed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Kiboko Labs Namaste! LMS allows Object Injection.This issue affects Namaste! LMS: from n/a through 2.6.3.

Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Oct 28, 2024

CVE-2024-50408 on NVD →

Namaste! LMS <= 2.6.3 - Authenticated (Subscriber+) PHP Object Injection

high

The Namaste! LMS plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.6.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...

CVSS:
8.8
Affected:
up to 2.6.3
Fixed in:
2.6.4
Disclosed:
Oct 24, 2024

CVE-2024-50408 on NVD →

Namaste! LMS <= 2.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 2.6.4
Fixed in:
2.6.4.1
Disclosed:
Oct 24, 2024

CVE-2024-50410 on NVD →

Namaste! LMS <= 2.6.2 - Authenticated (Student+) Stored Cross-Site Scripting

medium

The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with student-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Oct 24, 2024

CVE-2024-50409 on NVD →

Namaste! LMS <= 2.6.2 - Reflected Cross-Site Scripting

medium

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Oct 24, 2024

CVE-2024-50407 on NVD →

Namaste! LMS [namaste-lms] < 2.6.1.2 (closed)

unknown

[en] The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 2.6.1.2
Fixed in:
2.6.1.2
Disclosed:
Nov 15, 2023

CVE-2023-4602 on NVD →

Namaste! LMS <= 2.6.1.1 - Reflected Cross-Site Scripting

medium

The Namaste! LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'course_id' parameter in versions up to, and including, 2.6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 2.6.1.1
Fixed in:
2.6.1.2
Disclosed:
Nov 14, 2023

CVE-2023-4602 on NVD →

Namaste! LMS [namaste-lms] < 2.5.9.2 (closed)

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Namaste! LMS plugin <= 2.5.9.1 versions.

Affected:
up to 2.5.9.2
Fixed in:
2.5.9.2
Disclosed:
Apr 6, 2023

CVE-2023-24383 on NVD →

Namaste! LMS [namaste-lms] < 2.6 (closed)

unknown

[en] The Namaste! LMS WordPress plugin before 2.6 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 2.6
Fixed in:
2.6
Disclosed:
Mar 13, 2023

CVE-2023-0844 on NVD →

Namaste! LMS <= 2.5.9.9 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'accept_other_payment_methods', 'other_payment_methods' Parameters

medium

The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accept_other_payment_methods', 'other_payment_methods' parameters in versions up to 2.5.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level...

CVSS:
4.4
Affected:
up to 2.5.9.9
Fixed in:
2.6
Disclosed:
Mar 3, 2023

CVE-2023-0844 on NVD →

Namaste! LMS [namaste-lms] < 2.5.9.4 (closed)

unknown

[en] The Namaste! LMS WordPress plugin before 2.5.9.4 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 2.5.9.4
Fixed in:
2.5.9.4
Disclosed:
Feb 27, 2023

CVE-2023-0548 on NVD →

Namaste! LMS <= 2.5.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Namaste! LMS for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.5.9.3 due to insufficient input sanitization and output escaping on the currency setting value. This makes it possible for authenticated attackers, with administrative-level permissions an...

CVSS:
4.4
Affected:
up to 2.5.9.3
Fixed in:
2.5.9.4
Disclosed:
Jan 31, 2023

CVE-2023-0548 on NVD →

Namaste! LMS <= 2.5.9.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Namaste! LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Certificate Title value in versions up to, and including, 2.5.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to...

CVSS:
4.4
Affected:
up to 2.5.9.2
Fixed in:
2.5.9.2
Disclosed:
Jan 27, 2023

CVE-2023-24383 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database