CVE-2021-24713
בינונית 4.8
תיאור (מקור, אנגלית)
The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks
מדדים
- CVSS 3.1
-
4.8 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-7/10/2026
- CWE
- CWE-79
מוצרים מושפעים
cminds: video lessons manager
קישורים
- https://wpscan.com/vulnerability/4a90be69-41eb-43e9-962d-34316497b4df ExploitThird Party Advisory
- https://wpscan.com/vulnerability/4a90be69-41eb-43e9-962d-34316497b4df ExploitThird Party Advisory