CVE-2024-10010

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Dec 12, 2024

Summary

CVE-2024-10010: The LearnPress WordPress plugin, prior to version 4.2.7.2, contains a vulnerability that fails to sanitize and escape certain settings. This issue allows high privilege users, such as admins, to execute Stored Cross-Site Scripting attacks. Despite the disallowing of the unfiltered_html capability in multisite setups, this vulnerability remains a threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share