First published: Wed Jan 09 2019(Updated: )
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Thimpress Learnpress | <3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16175 is a SQL injection vulnerability in the LearnPress plugin for Wordpress prior to version 3.1.0.
The severity of CVE-2018-16175 is high, with a CVSS score of 7.2.
CVE-2018-16175 allows an attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors in LearnPress.
To fix CVE-2018-16175, upgrade LearnPress to version 3.1.0 or later.
You can find more information about CVE-2018-16175 in the official CVE database and on the WordPress plugin page for LearnPress.