CVE-2021-24951: LearnPress < 4.1.4 - Admin+ SQL Injection
Published Dec 13, 2021
·Updated
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues
Affected Software
1 affected component
thimpress Learnpress Wordpress<4.1.4
Event History
Dec 13, 2021
CVE Published
via MITRE·10:41 AM
Data Sourced
via MITRE·10:41 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24951.
2
What is the affected software?
The affected software is the LearnPress WordPress plugin before version 4.1.4.
3
What is the severity of CVE-2021-24951?
The severity of CVE-2021-24951 is critical.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 89.
5
How can I fix CVE-2021-24951?
To fix CVE-2021-24951, you should update the LearnPress WordPress plugin to version 4.1.4 or later.