CVE Database
/

CVE-2022-3360

Back to search

CVE-2022-3360

Published: Oct 31, 2022

Modified: May 6, 2025

PUBLISHED

Description

The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowledge of the site secrets, allowing them to generate a valid hash via the wp_hash() function.

VendorProductVersions

Unknown

LearnPress – WordPress LMS Plugin

affected
4.1.7.2 - < 4.1.7.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now