What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning Pro: from n/a through 3.9.
Explanation of Vulnerability in Simple Terms
02Summary
Ultimate Learning Pro versions 3.9 and earlier contain a SQL injection vulnerability in a database query that requires administrator-level access to exploit. An attacker with admin credentials can craft malicious input to read sensitive data from the database and potentially disrupt site availability. The vulnerability affects multiple components due to scope change, meaning other parts of the site may be impacted.
What an attacker can do
03Attacker Capabilities
Read sensitive database records and cause partial site unavailability.
Potential impact on your site
04Site Impact
Attackers with admin access can extract database contents and degrade site performance.
Conditions required to exploit
05Prerequisites
Administrator account access; no user interaction required.
Key dates
06Disclosure timeline
January 7, 2025
CVE published
April 28, 2026
Record updated