Input validation vulnerability in LMS – Education WordPress Theme 9.1

The LMS theme for WordPress has a security issue that allows attackers to access sensitive information from the database. This vulnerability is present in versions up to 9.1 because the user input is not properly protected and the existing SQL query is not adequately prepared. This means that attackers who are not logged in can add their own SQL queries to the existing ones, giving them access to private data.

Detected in:

LMS - Education WordPress Theme open vulnerable versions: >= * <= 9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.