LearnPress – WordPress LMS Plugin, e063dfb55310a5041b43fce7be6e8ecdce26e66c
- CVE, Research URL
- Application
- Published on
- Oct 05, 2020
- Research Description
- LearnPress – WordPress LMS Plugin for Create and Sell Online Courses [learnpress] < 3.2.7.3 LearnPress – WordPress LMS Plugin <= 3.2.7.2 - SQL Injection The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 3.2.7.2, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the IP parameter found in the duplicator functionality. This can be exploit by contributor+ level attackers to retrieve sensitive information from the database.
- Affected versions
-
max 3.2.7.3.
- Status
-
vulnerable