Executive brief
WP Learn Manager, a WordPress plugin used for creating and managing online courses, contains a security flaw that allows unauthorized individuals to inject malicious code into the website. If an administrator views the affected management page, this code can execute in their browser, potentially allowing the attacker to hijack the administrative session or modify site content. This could lead to a full takeover of the learning platform and exposure of student or instructor data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in WP Learn Manager version 1.1.2 due to a lack of input sanitization and missing authorization/CSRF checks in the user field management component. Unauthenticated attackers can send a specially crafted POST request to the 'jslm_fieldordering' page, injecting malicious scripts into the 'fieldtitle' parameter. The payload is stored in the database and executed whenever an administrator accesses the field ordering interface (/wp-admin/admin.php?page=jslm_fieldordering). This can lead to session hijacking, unauthorized administrative actions, or further exploitation of the WordPress environment. As of the advisory date, the plugin appears to be unmaintained.
Affected products
- JoomSky WP Learn Manager 1.1.2
Timeline
- 2021-07-02: disclosed: Vulnerability discovered and exploit details documented by Mohammed Adam.
- 2021-07-05: other: Exploit published on Exploit-DB.
- 2026-05-16: advisory: CVE published and added to NVD.