Learning Courses < 5.0 - Authenticated Cross-Site Scripting
medium
The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 5.0
- Fixed in:
- 5.0
- Disclosed:
- Dec 29, 2021
CVE-2021-24707 on NVD →
ND Learning <= 4.7 - Open Redirect
medium
The ND Learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVSS:
- 6.1
- Affected:
- up to 4.7
- Fixed in:
- 4.8
- Disclosed:
- Aug 6, 2019
CVE-2019-15775 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database