Vulnerability found in LearnPress – WordPress LMS Plugin

The LearnPress plugin for WordPress is vulnerable to a type of attack called “command injection” in all versions up to version 4.2.5.7. This is because the plugin is using a function called call_user_func with user input, which makes it possible for someone who is not logged in to the system to run any public function with one parameter. That could potentially lead to remote code execution.

Detected in:

LearnPress – WordPress LMS Plugin fixed vulnerable versions: >= * <= 4.2.5.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.