Input validation vulnerability in LearnPress – WordPress LMS Plugin 4.2.6.8.2

The LearnPress – WordPress LMS Plugin for WordPress has a security vulnerability in all versions up to 4.2.6.8.2. This vulnerability allows authorized users with Contributor-level access or higher to include and run any files on the server, potentially giving them access to sensitive information or the ability to execute code. This can happen even with files that are typically considered safe, like images.

Detected in:

LearnPress – WordPress LMS Plugin fixed vulnerable versions: >= * <= 4.2.6.8.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.