First published: Thu Apr 30 2020(Updated: )
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thimpress Learnpress | <=3.2.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6010 refers to a vulnerability in the LearnPress Wordpress plugin version prior to and including 3.2.6.7 that allows for SQL Injection.
CVE-2020-6010 has a severity rating of 8.8 (high).
CVE-2020-6010 affects the LearnPress Wordpress plugin versions prior to and including 3.2.6.7.
The CWE for CVE-2020-6010 is CWE-89 (SQL Injection).
You can find more information about CVE-2020-6010 at the following references: http://packetstormsecurity.com/files/163536/WordPress-LearnPress-SQL-Injection.html, https://plugins.trac.wordpress.org/browser/learnpress/trunk/readme.txt?rev=2288975, https://research.checkpoint.com/2020/e-learning-platforms-getting-schooled-multiple-vulnerabilities-in-wordpress-most-popular-learning-management-system-plugins/