LearnPress – Unauthenticated SQL Injection Vulnerability in WordPress LMS Plugin

ISGroup Cybersecurity

A major vulnerability with a severity score of 10.0 has been identified, affecting a large number of WordPress instances. The flaw allows an unauthenticated attacker to execute malicious commands on the database, exposing sensitive information. More than 130,000 cases have been detected via ZoomEye.

Productlearnpress
Date2024-09-17 10:59:19

Technical Summary

The LearnPress – WordPress LMS plugin for WordPress is affected by a critical SQL Injection vulnerability via the c_only_fields parameter in all versions up to 4.2.7. This flaw allows unauthenticated attackers to access sensitive information contained in the database, posing a serious security risk. Over 130,000 vulnerable instances have been detected on ZoomEye.

Recommendations

Update to a version later than 4.2.7.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert