Extension WordPress
Vulnérabilités LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, page 2
Cette page rassemble les failles publiées pour LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
72 fiches
LearnPress – WordPress LMS Plugin <= 4.2.7.5 – Authenticated (Admin+) Stored Cross-Site Scripting
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.2.7.5
4.2.7.5.1
29/01/2025
LearnPress – WordPress LMS Plugin <= 4.2.7.5 – Authenticated (Admin+) Stored Cross-Site Scripting
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.2.7.5
4.2.7.5.1
29/01/2025
LearnPress – WordPress LMS Plugin <= 4.2.7.5 – Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.7.5 due to insufficient input sanitization and output escaping of a lesson name. This makes it…
*-4.2.7.5
4.2.7.5.1
24/01/2025
LearnPress <= 4.2.7.1 – Authenticated (Subscriber+) Open Redirect
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.2.7.1. This is due to insufficient validation on a redirect url supplied. This makes it possible for…
*-4.2.7.1
4.2.7.2
24/01/2025
LearnPress – WordPress LMS Plugin <= 4.2.7.3 – Course Material Sensitive Information Exposure via REST API
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to extract potentially sensitive paid course…
*-4.2.7.3
4.2.7.4
09/12/2024
LearnPress <= 4.2.7.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.1 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.2.7.1
4.2.7.2
21/11/2024
LearnPress <= 4.2.7.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.7.1 due to insufficient input sanitization and output escaping. This makes it possible…
*-4.2.7.1
4.2.7.2
21/11/2024
LearnPress – WordPress LMS Plugin <= 4.2.7 – Unauthenticated SQL Injection via 'c_only_fields'
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the…
*-4.2.7
4.2.7.1
11/09/2024
LearnPress – WordPress LMS Plugin <= 4.2.7 – Unauthenticated SQL Injection via 'c_fields'
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the…
*-4.2.7
4.2.7.1
11/09/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.9.3 – Authenticated (Contributor+) SQL Injection via order Parameter
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 4.2.6.9.3 due to insufficient escaping on the user supplied parameter and lack…
*-4.2.6.9.3
4.2.6.9.4
07/08/2024
LearnPress <= 4.2.6.8.2 – Authenticated (Subscriber+) Insecure Direct Object Reference
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.8.2 due to missing validation on a user controlled key. This makes it possible for…
*-4.2.6.8.2
4.2.6.9
01/08/2024
LearnPress <= 4.2.6.8.2 – Cross-Site Request Forgery
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6.8.2. This is due to missing or incorrect nonce validation on an unknown function. This makes…
*-4.2.6.8.2
4.2.6.9
01/08/2024
LearnPress <= 4.2.6.8.2 – Authenticated (Contributor+) Local File Inclusion
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the 'render_content_block_template' function. This makes it possible for authenticated attackers, with Contributor-level access and…
*-4.2.6.8.2
4.2.6.9
24/07/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 – Unauthenticated Bypass to User Registration
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This…
*-4.2.6.8.1
4.2.6.8.2
01/07/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 – Missing Authorization to Unauthenticated User Registration Bypass
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for…
*-4.2.6.8.1
4.2.6.8.2
01/07/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.8 – Basic Information Disclosure via JSON API
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to…
*-4.2.6.8
4.2.6.8.1
04/06/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.2.6.6 due to insufficient input sanitization and output escaping. This makes it…
*-4.2.6.6
4.2.6.7
21/05/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_html’ parameter in all versions up to, and including, 4.2.6.5 due to insufficient input sanitization and output escaping. This makes it…
*-4.2.6.5
4.2.6.6
09/05/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.5 – Unauthenticated Time-Based SQL Injection
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of…
*-4.2.6.5
4.2.6.6
09/05/2024
LearnPress – WordPress LMS Plugin <= 4.2.6.5 – Unauthenticated Bypass to User Registration
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes…
*-4.2.6.5
4.2.6.6
09/05/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.