Input validation vulnerability in LearnPress – WordPress LMS Plugin 4.2.7

The LearnPress plugin for WordPress is at risk of being hacked through a feature called ‘c_fields’ in the plugin’s code. This can happen in all versions up to 4.2.7. The problem is caused by not properly protecting the user’s input and not properly preparing the existing code. This means that people who are not logged in can add their own malicious code to the existing code, which could lead to them getting access to private information from the database.

Detected in:

LearnPress – WordPress LMS Plugin fixed vulnerable versions: >= * <= 4.2.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.