VYPR

WP Learn Manager

by WordPress

CVEs (2)

  • CVE-2021-47975HigMay 16, 2026
    risk 0.47cvss 7.2epss 0.00

    WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the `fieldtitle` parameter. Attackers can submit POST requests to the jslm_fieldordering page with XSS payloads in the fieldtitle…

  • CVE-2026-12153CriJul 8, 2026
    risk 0.00cvss 9.8epss 0.00

    The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…