CVE-2021-24308
Last modified
CVE-2021-24308 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.. EPSS estimates a 3.25% chance of exploitation in the next 30 days.
Description
The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lifterlms | Lifterlms | < 4.21.1 |
References
- https://packetstormsecurity.com/files/162856/WordPress-LifterLMS-4.21.0-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/gocodebox/lifterlms/releases/tag/4.21.1Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/f29f68a5-6575-441d-98c9-867145f2b082Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/162856/WordPress-LifterLMS-4.21.0-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/gocodebox/lifterlms/releases/tag/4.21.1Release Notes, Third Party Advisory
- https://wpscan.com/vulnerability/f29f68a5-6575-441d-98c9-867145f2b082Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-24308?
How severe is CVE-2021-24308?
How do I fix CVE-2021-24308?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-24302The Hana Flv Player WordPress plugin through 3.1.3 is vulner…5.4
- CVE-2021-24303The JiangQie Official Website Mini Program WordPress plugin …8.8
- CVE-2021-24304The Newsmag WordPress theme before 5.0 does not sanitise the…6.1
- CVE-2021-24305The Target First WordPress Plugin v2.0, also previously know…6.1
- CVE-2021-24306The Ultimate Member – User Profile, User Registration, Login…5.4
- CVE-2021-24307The All in One SEO – Best WordPress SEO Plugin – Easily Impr…8.8
- CVE-2021-24309The "Schedule Name" input in the Weekly Schedule WordPress p…5.4
- CVE-2021-2431Vulnerability in the Oracle Outside In Technology product of…7.5
- CVE-2021-24310The Photo Gallery by 10Web - Mobile-Friendly Image Gallery W…4.8
- CVE-2021-24311The wp_ajax_upload-remote-file AJAX action of the External M…8.8
- CVE-2021-24312The parameters $cache_path, $wp_cache_debug_ip, $wp_super_ca…7.2
- CVE-2021-24313The WP Prayer WordPress plugin before 1.6.2 provides the fun…5.4
Are you affected by CVE-2021-24308?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
