Input validation vulnerability in LearnPress – WordPress LMS Plugin 4.2.5.4

The LearnPress – WordPress LMS Plugin is a plugin for WordPress websites that could be vulnerable to a type of attack known as Reflected Cross-Site Scripting. This vulnerability affects all versions of the plugin from 4.2.5.3 and earlier, and it occurs because of a lack of security measures in place to protect against malicious input and output. This means that an attacker could potentially inject malicious web scripts into pages that are then executed when a user clicks on a link that the attacker has sent them.

Detected in:

LearnPress – WordPress LMS Plugin fixed vulnerable versions: >= * < 4.2.5.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.