The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.3 via class-lp-rest-material-controller.php. This makes it possible for unauthenticated attackers to extract potentially sensitive paid course material.
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset/3200780/learnpress | Broken Link |
https://www.wordfence.com/threat-intel/vulnerabilities/id/7bd43980-9193-4a63-adba-720dd1b11699?source=cve | Third Party Advisory |
Configurations
History
14 Jan 2025, 21:36
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:* | |
Summary |
|
|
References | () https://plugins.trac.wordpress.org/changeset/3200780/learnpress - Broken Link | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/7bd43980-9193-4a63-adba-720dd1b11699?source=cve - Third Party Advisory | |
First Time |
Thimpress
Thimpress learnpress |
10 Dec 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-10 13:15
Updated : 2025-01-14 21:36
NVD link : CVE-2024-11868
Mitre link : CVE-2024-11868
CVE.ORG link : CVE-2024-11868
JSON object : View
Products Affected
thimpress
- learnpress
CWE