WordPress Plugin Vulnerabilities
LifterLMS < 4.21.1 - Reflected Cross-Site Scripting (XSS) via Coupon Code in Checkout
Description
The plugin did not properly sanitise the coupon code during checkout before outputting in back the error message in the page, leading to a reflected Cross-Site Scripting issue
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Ashish Jha
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2021-05-10 (about 4 years ago)
Added
2021-05-10 (about 4 years ago)
Last Updated
2021-05-12 (about 4 years ago)