WordPress LearnPress Plugin <= 4.1.7.3.2 is vulnerable to SQL Injection
CVE-2022-45820
9.1CRITICAL
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 26 January 2023
What is CVE-2022-45820?
The LearnPress plugin, a popular Learning Management System (LMS) for WordPress, contains a SQL injection vulnerability that allows attackers to manipulate database queries. This flaw could enable unauthorized access to sensitive data, including user details and site configurations. The issue affects versions of the plugin up to and including 4.1.7.3.2, necessitating immediate updates to mitigate potential exploitation. Site administrators should apply the latest patches to ensure robust security.
Affected Version(s)
LearnPress – WordPress LMS Plugin <= 4.1.7.3.2