WordPress Plugin Vulnerabilities

LifterLMS < 4.21.1 - Reflected Cross-Site Scripting (XSS) via Coupon Code in Checkout

Description

The plugin did not properly sanitise the coupon code during checkout before outputting in back the error message in the page, leading to a reflected Cross-Site Scripting issue

Affects Plugins

Fixed in 4.21.1

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Ashish Jha
Verified
Yes

Timeline

Publicly Published
2021-05-10 (about 4 years ago)
Added
2021-05-10 (about 4 years ago)
Last Updated
2021-05-12 (about 4 years ago)

Other