CVE-2022-1250

MEDIUM

LifterLMS PayPal < 1.4.0 - Reflected Cross-Site Scripting via Payment Confirmation Page

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-1250. PoCs published by tomorroisnew.

Description

The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirmation page before outputting them back in the page, leading to a Reflected Cross-Site Scripting issue

Exploits (1)

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/1f8cb0b9-7447-44db-8d13-292db5b17718

Scores

CVSS v3 6.1
EPSS 0.0090
EPSS Percentile 54.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
lifterlms/lifterlms < 1.4.0
Published May 02, 2022
Tracked Since Feb 18, 2026