CVE-2021-24621

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/09/2021
Last modified:
23/09/2021

Description

The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:stratospheredigital:wp_courses_lms:*:*:*:*:*:wordpress:*:* 2.0.44 (excluding)