cleantalk
Vulnerabilities and Security Researches

LearnPress – WordPress LMS Plugin, e063dfb55310a5041b43fce7be6e8ecdce26e66c

Published on
Oct 05, 2020
Research Description
LearnPress &#8211; WordPress LMS Plugin for Create and Sell Online Courses [learnpress] < 3.2.7.3 LearnPress – WordPress LMS Plugin <= 3.2.7.2 - SQL Injection The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 3.2.7.2, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the IP parameter found in the duplicator functionality. This can be exploit by contributor+ level attackers to retrieve sensitive information from the database.
Affected versions
max 3.2.7.3.
Status
vulnerable