Record summary

CVE-2024-13619 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 20, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

LifterLMS

Default status: unaffected

CVE ListBefore 8.0.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLifterLMS < 8.0.1 - Cross-Site ScriptingCVSS 6.1

LifterLMS WordPress plugin before 8.0.1 contains a reflected XSS caused by unsanitized and unescaped parameter output, letting attackers execute scripts against high privilege users such as admin via a crafted request.

Impact

Attackers can execute scripts in admin users' browsers, potentially leading to account compromise or unauthorized actions.

Remediation

Update to version 8.0.1 or later.

WeaknessesCWE-79
AuthorsShivam Kamboj
Template tagscvecve2024wordpresswpwp-pluginlifterlmsxssauthenticated
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
FOFA: body="lifterlms"

Source: ProjectDiscovery

References

2