QID 730709

Date Published: 2023-01-30

QID 730709: WordPress Plugin LearnPress Multiple Security Vulnerabilities

LearnPress is a comprehensive WordPress LMS Plugin for WordPress which can be used to easily create and sell courses online.

CVE-2022-47615: An unauthenticated local file inclusion vulnerability could allow an attacker to display contents of local files stored on the web server, potentially exposing credentials, authorization tokens, and API keys.
CVE-2022-45808: An unauthenticated SQL injection vulnerability could allow an attacker to insert malicious code, potentially leading to sensitive information disclosure, data modification, and arbitrary code execution.
CVE-2022-45820: An authenticated SQL injection vulnerability could allow an attacker to insert malicious code, potentially leading to sensitive information disclosure, data modification, and arbitrary code execution.
Affected Versions:
LearnPress Plugin versions before and including 4.1.7.3.2

QID Detection Logic(Unauthenticated): This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the LearnPress plugin.

Successful exploitation of this vulnerability may allow an attacker to insert malicious code, potentially leading to sensitive information disclosure, data modification, arbitrary code execution, display contents of local files stored on the web server, potentially exposing credentials, authorization tokens, and API keys.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are requested to update to LearnPress Plugin 4.2.0 or later to mitigate this vulnerability.

    Vendor References

    CVEs related to QID 730709

    Software Advisories
    Advisory ID Software Component Link
    LearnPress Plugin Release Notes URL Logo wordpress.org/plugins/learnpress/#developers