SQL Injection Vulnerability in LearnPress Plugin for WordPress
CVE-2026-77823
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-77823?
The LearnPress plugin for WordPress exhibits a serious SQL Injection vulnerability through the 'orderby' parameter in the export_order_csv AJAX action. This issue arises due to inadequate escaping of user inputs and poor preparation of SQL queries within the plugin's code. Specifically, while certain values like 'date' and 'title' are properly normalized, other inputs provided by authenticated users with administrator-level access may directly impact the SQL query construction. As a result, these users can inject additional SQL commands that manipulate existing database queries, ultimately compromising sensitive information stored in the database.
Affected Version(s)
LearnPress β WordPress LMS Plugin for Create and Sell Online Courses 0 <= 4.4.4