Vulnerabilities > ND Learning Project

DATE CVE VULNERABILITY TITLE RISK
2022-02-01 CVE-2021-24707 Cross-site Scripting vulnerability in Nd-Learning Project Nd-Learning
The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
network
low complexity
nd-learning-project CWE-79
4.8