Input validation vulnerability in LearnPress – WordPress LMS Plugin 4.2.6.5

The LearnPress plugin, which is used for creating online courses on WordPress, has a security vulnerability. This vulnerability, which exists in versions up to 4.2.6.5, allows attackers to inject their own SQL queries and access sensitive information from the database. This can be done by manipulating the ‘term_id’ parameter and taking advantage of insufficient security measures in the plugin. This poses a risk for users who are not logged in to the website.

Detected in:

LearnPress – WordPress LMS Plugin fixed vulnerable versions: >= * <= 4.2.6.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.