CVE-2024-31241: WordPress LearnPress Export Import plugin <= 4.0.3 - Auth. SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress LearnPress Export Import.This issue affects LearnPress Export Import: from n/a through 4.0.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31241?
CVE-2024-31241 is classified as a critical SQL injection vulnerability affecting versions of LearnPress Export Import up to 4.0.3.
How do I fix CVE-2024-31241?
To fix CVE-2024-31241, update the LearnPress Export Import plugin to the latest version beyond 4.0.3.
What types of attacks can CVE-2024-31241 allow?
CVE-2024-31241 can allow attackers to execute arbitrary SQL commands, potentially compromising the database.
Which versions are affected by CVE-2024-31241?
CVE-2024-31241 affects LearnPress Export Import plugin versions from release through 4.0.3.
Does CVE-2024-31241 affect other software apart from LearnPress?
CVE-2024-31241 is specifically related to the ThimPress LearnPress Export Import plugin and does not affect other software.