First published: Mon Dec 13 2021(Updated: )
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Thimpress Learnpress | <4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24951.
The affected software is the LearnPress WordPress plugin before version 4.1.4.
The severity of CVE-2021-24951 is critical.
The CWE ID for this vulnerability is 89.
To fix CVE-2021-24951, you should update the LearnPress WordPress plugin to version 4.1.4 or later.