LearnPress – WordPress LMS(用于创建和销售在线课程)插件存在反射型 DOM 跨站脚本(DOM-Based Cross-Site Scripting, XSS)漏洞。该漏洞存在于所有版本号不超过 4.4.7 的版本中,原因是输入清理和输出转义处理不足。漏洞存在于名为 "orderby" 的参数中,这使得未认证的攻击者能够向网页中注入任意 Web 脚本,如果攻击者成功诱使用户执行某些操作(例如点击恶意链接),这些脚本将会被执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | ≤ 4.4.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thimpress | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | 0 ~ 4.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet