module
Wordpress LearnPress current_items Authenticated SQLi
| Disclosed | Created |
|---|---|
| Apr 29, 2020 | Aug 26, 2021 |
Disclosed
Apr 29, 2020
Created
Aug 26, 2021
Description
LearnPress, a learning management plugin for WordPress,
prior to 3.2.6.8 is affected by an authenticated SQL injection via the
current_items parameter of the post-new.php page.
prior to 3.2.6.8 is affected by an authenticated SQL injection via the
current_items parameter of the post-new.php page.
Authors
h00die
Omri Herscovici
Sagi Tzadik
nhattruong
Omri Herscovici
Sagi Tzadik
nhattruong
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.