Extension WordPress
Vulnérabilités LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, page 4
Cette page rassemble les failles publiées pour LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
72 fiches
LearnPress <= 4.1.3 – Authenticated SQL Injection
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues
[*, 4.1.4)
4.1.4
09/11/2021
LearnPress <= 4.1.3.1 – Stored Cross-Site Scripting via $custom_profile
The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up…
*-4.1.3.1
4.1.3.2
18/10/2021
LearnPress <= 4.1.3 – Authenticated Stored Cross-Site Scripting
The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowed
*-4.1.3
4.1.3.1
20/09/2021
LearnPress <= 3.2.6.7 – SQL Injection
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
*-3.2.6.7
3.2.6.8
19/07/2021
LearnPress – WordPress LMS Plugin <= 3.2.7.2 – SQL Injection
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 3.2.7.2, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the…
*-3.2.7.2
3.2.7.3
05/10/2020
LearnPress <= 3.2.7.2 – Reflected Cross-Site Scripting
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.7.2.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
[*, 3.2.7.3)
3.2.7.3
08/09/2020
LearnPress <= 3.2.6.8 – Privilege Escalation via accept-to-be-teacher action parameter
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
*-3.2.6.8
3.2.6.9
20/04/2020
LearnPress <= 3.2.6.8 – Authenticated Page Creation and Status Modification
Versions below 3.2.6.9 allow an attacker to publish or trash any existing post or page, or even set it to a nonexistent status, at which point it would no longer appear on the site or be accessible from…
*-3.2.6.8
3.2.6.9
19/04/2020
LearnPress <= 3.2.6.6 – Privilege Escalation
be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any user can change its role…
*-3.2.6.6
3.2.6.8
16/03/2020
LearnPress <= 3.0.12 – Cross-Site Scripting
Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
*-3.0.12
3.1.0
09/11/2018
LearnPress <= 3.0.12 – Open Redirect
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
*-3.0.12
3.1.0
09/11/2018
LearnPress <= 3.0.12 – Authenticated SQL Injection
SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
*-3.0.12
3.1.0
09/11/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.