S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 26, 2025

CVE-2024-8529 Scanner

CVE-2024-8529 Scanner - SQL Injection (SQLi) vulnerability in LearnPress

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8529
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesby thimpress
0
learnpressby thimpress
0
Updated Aug 22, 2026View on NVD →
Detail

LearnPress is a comprehensive Learning Management System (LMS) plugin used on WordPress platforms, allowing educators and institutions to create, manage, and sell courses online. It is popular among educational organizations for its robust features and ease of use in deploying digital learning solutions. LearnPress supports a wide array of integrations, providing a seamless learning experience while enabling scalability to meet growing educational demands. The plugin is employed by tutors, training institutes, and professional educators globally to facilitate seamless online and offline learning. Its versatile tools have made it an essential component in e-learning environments, supporting a variety of content formats and interactive features for enhanced learning.

The SQL Injection vulnerability in LearnPress, prior to version 4.2.7.1, allows attackers to manipulate SQL queries through the 'c_fields' parameter. This critical flaw enables unauthorized individuals to access the /wp-json/lp/v1/courses/archive-course REST API endpoint and execute arbitrary SQL commands. By exploiting this vulnerability, attackers can extract sensitive information from the database without requiring authentication credentials. SQL Injection attacks can compromise data integrity, allowing attackers to retrieve, delete, or modify database content maliciously. The vulnerability highlights the risks associated with inadequate validation of user-input data in web applications. Effective patching and input sanitation measures are critical to mitigating such threats in WordPress plugins like LearnPress.

Technical details surrounding the vulnerability in LearnPress involve the manipulation of SQL queries via unsanitized inputs. Specifically, the 'c_fields' parameter in the REST API endpoint is susceptible to exploitation through injection attacks. Attackers can craft payloads including time-based SQL injection techniques to extract data from the database, revealing sensitive information and potentially causing database disruption. The endpoint's inability to properly validate and sanitize SQL inputs exposes the system to unauthorized data extraction attempts. Such vulnerabilities serve as an entry point for further attacks, leveraging the unprotected database commands for malicious activities. Addressing this vulnerability mandates updating to newer, secure versions of the LearnPress plugin, along with implementing rigorous input validation protocols.

Exploiting this SQL Injection vulnerability can lead to significant security breaches in affected systems running LearnPress. Attackers gaining unauthorized access to sensitive information, such as user data and course content, pose privacy and data protection concerns for educational institutions relying on this plugin. Further ramifications could involve data manipulation, unauthorized data disclosure, and potential service disruption. Successful exploitation can also facilitate further attacks, such as privilege escalation or facilitating malware distribution by compromising database integrity. Institutions using LearnPress must prioritize the mitigation of this vulnerability to safeguard data confidentiality, integrity, and availability.

REFERENCES:

Solution Advice
  • Update the LearnPress plugin to version 4.2.7.1 or later to patch the vulnerability.
  • Implement Input validation and sanitization mechanisms on fields exposed to user input in the REST API.
  • Regularly review and test security protocols to identify potential vulnerabilities in WordPress installations.
  • Employ Web Application Firewalls (WAF) to detect and block malicious SQL injection attempts.
  • Conduct periodic security audits to ensure compliance with best practices in application security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.