CVE Database
/

CVE-2021-24951

Back to search

CVE-2021-24951

Published: Dec 13, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues

VendorProductVersions

Unknown

LearnPress – WordPress LMS Plugin

affected
4.1.4 - < 4.1.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now