LifterLMS WordPress plugin before 8.0.1 contains a reflected XSS caused by unsanitized and unescaped parameter output, letting attackers execute scripts against high privilege users such as admin via a crafted request.
id: CVE-2024-13619
info:
name: LifterLMS < 8.0.1 - Cross-Site Scripting
author: Shivam Kamboj
...