CVE-2023-28777: WordPress LearnDash LMS plugin <= 4.5.3 - Auth. SQL Injection (SQLi) vulnerability
Published Oct 31, 2023
·Updated
A vulnerability in LearnDash LearnDash LMS sfwd-lms.This issue affects LearnDash LMS: from n/a through <= 4.5.3.
Affected Software
1 affected component
LearnDash LearnDash Wordpress<=4.5.3
Remediation
Information
Update to 4.5.3.1 or a higher version.
Event History
Oct 31, 2023
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-28777.
2
What is the title of this vulnerability?
The title of this vulnerability is 'WordPress LearnDash LMS Plugin <= 4.5.3 is vulnerable to SQL Injection'.
3
What is the severity of CVE-2023-28777?
The severity of CVE-2023-28777 is high with a severity value of 8.8.
4
How does CVE-2023-28777 affect LearnDash LMS?
CVE-2023-28777 allows SQL Injection in LearnDash LMS versions up to and including 4.5.3.
5
Is there a patch or fix available for CVE-2023-28777?
Yes, a patch is available for CVE-2023-28777. You can find more information at the following link: [PatchStack - WordPress LearnDash LMS Plugin 4.5.3 Contributor SQL Injection Vulnerability](https://patchstack.com/database/vulnerability/sfwd-lms/wordpress-learndash-lms-plugin-4-5-3-contributor-sql-injection-vulnerability?_s_id=cve).