WordPress Plugin Vulnerabilities

LifterLMS < 3.35.1 - Unauthenticated Options Import

Description

Unauthenticated Options Import, which could lead to
- Website Redirection
- Administrator Account Creation
- Content Injection
- Stored XSS

The issues have been reported as fixed in 3.35.0. However v3.35.1 added additional input sanitisation and filtering.

Affects Plugins

Fixed in 3.35.1

References

Classification

Miscellaneous

Original Researcher
Jerome Bruandet (nintechnet.com)
Verified
No

Timeline

Publicly Published
2019-09-09 (about 4 years ago)
Added
2019-09-09 (about 4 years ago)
Last Updated
2020-09-22 (about 3 years ago)

Other