Input validation vulnerability in LearnPress Export Import 4.0.3

The LearnPress Export Import plugin for WordPress has a security issue that can put websites at risk. This vulnerability, called Reflected Cross-Site Scripting, affects all versions up to 4.0.3. It happens because the plugin does not properly clean up or protect the information it receives and shows on the website. This means that someone who is not authorized can insert harmful code into a page on the website. They can do this by tricking a user into clicking on a link.

Detected in:

LearnPress – Backup & Migration Tool fixed vulnerable versions:
LearnPress Export Import – WordPress extension for LearnPress open vulnerable versions: >= * <= 4.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.