Extension WordPress

Vulnérabilités LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, page 4

Cette page rassemble les failles publiées pour LearnPress – WordPress LMS Plugin for Create and Sell Online Courses, leurs plages de versions affectées et les correctifs signalés dans la base locale.

72Vulnérabilités
9Critiques
72Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

72 fiches

CVE-2021-39348 Moyenne · 5,5
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

LearnPress <= 4.1.3.1 – Stored Cross-Site Scripting via $custom_profile

The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom_profile parameter found in the ~/inc/admin/views/backend-user-profile.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up…

Versions affectées

*-4.1.3.1

Correctif

4.1.3.2

Publication

18/10/2021

CVE-2021-24702 Moyenne · 4,8
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

LearnPress <= 4.1.3 – Authenticated Stored Cross-Site Scripting

The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowed

Versions affectées

*-4.1.3

Correctif

4.1.3.1

Publication

20/09/2021

Vulnérabilité Élevée · 8,8
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

LearnPress – WordPress LMS Plugin <= 3.2.7.2 – SQL Injection

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including 3.2.7.2, that makes it possible for attackers to append arbitrary SQL queries into an existing query via the…

Versions affectées

*-3.2.7.2

Correctif

3.2.7.3

Publication

05/10/2020

Vulnérabilité Moyenne · 6,1
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

LearnPress <= 3.2.7.2 – Reflected Cross-Site Scripting

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.7.2.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

[*, 3.2.7.3)

Correctif

3.2.7.3

Publication

08/09/2020

CVE-2020-7916 Élevée · 7,1
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

LearnPress <= 3.2.6.6 – Privilege Escalation

be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any user can change its role…

Versions affectées

*-3.2.6.6

Correctif

3.2.6.8

Publication

16/03/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités