CVE-2023-5558
LearnPress < 4.2.5.5 - Reflected Cross-Site Scripting
Record summary
CVE-2023-5558 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 23, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LearnPressDefault status: unaffected | CVE List | Before 4.2.5.5 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLearnPress < 4.2.5.5 - Cross-Site ScriptingCVSS 6.1
The LearnPress WordPress plugin before 4.2.5.5 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Impact
Allows attackers to execute malicious scripts in the context of the victim's browser.
Remediation
Update LearnPress WordPress Plugin to the latest version to mitigate the vulnerability.
Source: ProjectDiscovery