<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2021-24308_WordPress_Plugin_LifterLMS_4.21.0_XSS%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2021-24308 WordPress Plugin LifterLMS 4.21.0 XSS漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2021-24308_WordPress_Plugin_LifterLMS_4.21.0_XSS%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2021-24308_WordPress_Plugin_LifterLMS_4.21.0_XSS%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-25T08:32:07Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2021-24308_WordPress_Plugin_LifterLMS_4.21.0_XSS%E6%BC%8F%E6%B4%9E&amp;diff=3599&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; # Exploit Title: WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)  # Date: 2021-05-10 # Exploit Author: Captain_hook # Vendor Homepage: http...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2021-24308_WordPress_Plugin_LifterLMS_4.21.0_XSS%E6%BC%8F%E6%B4%9E&amp;diff=3599&amp;oldid=prev"/>
		<updated>2021-05-28T09:45:16Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; # Exploit Title: WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)  # Date: 2021-05-10 # Exploit Author: Captain_hook # Vendor Homepage: http...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS) &lt;br /&gt;
# Date: 2021-05-10&lt;br /&gt;
# Exploit Author: Captain_hook&lt;br /&gt;
# Vendor Homepage: https://lifterlms.com/&lt;br /&gt;
# Software Link: https://github.com/gocodebox/lifterlms/releases/tag/4.21.0&lt;br /&gt;
# Version: LifterLMS &amp;lt; 4.21.1&lt;br /&gt;
# Tested on: ANY&lt;br /&gt;
# CVE : CVE-2021-24308&lt;br /&gt;
&lt;br /&gt;
#Summary:&lt;br /&gt;
&lt;br /&gt;
The 'State' field of the Edit profile page of the LMS by LifterLMS â€“ Online Course, Membership &amp;amp; Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.&lt;br /&gt;
&lt;br /&gt;
#Proof_of_Concept:&lt;br /&gt;
&lt;br /&gt;
1- As a Lowest Privilege user go to the edit account page of the LMS&lt;br /&gt;
(e.g https://example.com/my-courses/edit-account/)&lt;br /&gt;
&lt;br /&gt;
2- Put Your XSS payload in State parameter and save your edits, such&lt;br /&gt;
as &amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(/XSS/)&amp;lt;/script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3- The XSS will be stored and triggered in the about section of the profile: (e.g  https://example.com/directory/[user_name]/) (Note): The XSS will also be triggered in the admin dashboard when viewing the user details, for example https://example.com/wp-admin/admin.php?page=llms-reporting&amp;amp;tab=students&amp;amp;stab=information&amp;amp;student_id=2&lt;br /&gt;
&lt;br /&gt;
Refernces:&lt;br /&gt;
&lt;br /&gt;
https://github.com/gocodebox/lifterlms/releases/tag/4.21.0&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>