CVE-2022-45820
Published on: Not Yet Published
Last Modified on: 02/01/2023 03:13:00 PM UTC
Certain versions of Learnpress from Thimpress contain the following vulnerability:
SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
- CVE-2022-45820 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
ThimPress - LearnPress – WordPress LMS Plugin version = n/a
CVSS3 Score: 8.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
WordPress LearnPress plugin <= 4.1.7.3.2 - Auth. SQL Injection (SQLi) vulnerability - Patchstack | patchstack.com text/html |
![]() |
Multiple Critical Vulnerabilities Fixed In LearnPress Plugin Version | patchstack.com text/html |
![]() |
Related QID Numbers
- 730709 WordPress Plugin LearnPress Multiple Security Vulnerabilities
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Thimpress | Learnpress | All | All | All | All |
- cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Potentially Critical CVE Detected! CVE-2022-45820 SQL Injection (SQLi) vulnerability in LearnPress – WordPres… twitter.com/i/web/status/1… | 2023-01-24 10:55:59 |
![]() |
CVEnew: CVE-2022-45820 SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 version… twitter.com/i/web/status/1… | 2023-01-24 11:13:21 |
![]() |
Xəbərdarlıq: "WordPress"in "LearnPress" əlavəsində 3 kritik boşluq (CVE-2022-47615, CVE-2022-45808, CVE-2022-45820)… twitter.com/i/web/status/1… | 2023-01-25 12:33:44 |
![]() |
• CVE-2022-45820 (CVSS 3.1: 9.1, Crítico): una vulnerabilidad de inyección de SQL podría permitir que un actor mali… twitter.com/i/web/status/1… | 2023-01-25 15:42:25 |
![]() |
CVE-2022-45820 : SQL Injection SQLi vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.... cve.report/CVE-2022-45820 | 2023-01-26 21:24:40 |