What the vulnerability does
01Description
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
What the vulnerability does
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
Explanation of Vulnerability in Simple Terms
LearnPress versions up to 4.1.7.3.2 contain a SQL injection vulnerability in the plugin's database queries. An attacker can inject malicious SQL code through user input without authentication. This allows reading sensitive data from the WordPress database, modifying course content or user records, and potentially disrupting site availability. All sites running affected versions should update immediately.
What an attacker can do
Read, modify, or delete data from the WordPress database without logging in.
Potential impact on your site
Attackers can steal student data, course content, and credentials; modify grades and course settings; or crash the database.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities