LearnPress <= 4.2.5.7 - Command Injection
78Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.1epss 8.5%
from disclosure to weapon85 days
Published on NVDJan 11
1st PoC+85d
VulnCheckJan 4
exploitation probability
8.5%top 5% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
public PoCs found — 1
vulncheckvulncheck.com/xdb/15d8215b2679unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.