WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbitrary JavaScript when administrators view the field ordering interface.
Metrics
Affected Vendors & Products
References
History
Sat, 16 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the fieldtitle parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle field to execute arbitrary JavaScript when administrators view the field ordering interface. | |
| Title | WordPress Plugin WP Learn Manager 1.1.2 Stored XSS | |
| First Time appeared |
Wplearnmanager
Wplearnmanager wp Learn Manager |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.0:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.2:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.3:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.4:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.5:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.6:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.7:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.8:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.0.9:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.1.0:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.1.1:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.1.2:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.1.3:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.1.4:*:*:*:*:wordpress:*:* cpe:2.3:a:wplearnmanager:wp_learn_manager:1.1.5:*:*:*:*:wordpress:*:* |
|
| Vendors & Products |
Wplearnmanager
Wplearnmanager wp Learn Manager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-16T15:26:15.528Z
Reserved: 2026-05-16T14:36:27.726Z
Link: CVE-2021-47975
No data.
Status : Received
Published: 2026-05-16T16:16:22.973
Modified: 2026-05-16T16:16:22.973
Link: CVE-2021-47975
No data.
OpenCVE Enrichment
Updated: 2026-05-16T17:15:26Z