---
id: CVE-2021-24713
title: >-
  The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons
  Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape
  values when updating their settings, which could allow high privilege users to
  perfor…
summary: >-
  The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons
  Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape
  values when updating their settings, which could allow high privilege users to
  perfor…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: cminds
product: video_lessons_manager
affected:
  - video_lessons_manager < 1.7.2
patched:
  - video_lessons_manager 1.7.2
published: '2021-11-23'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-24713'
references:
  - url: 'https://wpscan.com/vulnerability/4a90be69-41eb-43e9-962d-34316497b4df'
    label: contact@wpscan.com
  - url: 'https://wpscan.com/vulnerability/4a90be69-41eb-43e9-962d-34316497b4df'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00617
epssPercentile: 0.47294
ingestedAt: '2026-08-24T16:07:20.436Z'
---

## Overview

The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks

## Affected

- `video_lessons_manager < 1.7.2`

## Remediation

Upgrade past the affected range:

- `video_lessons_manager 1.7.2`
