S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jul 22, 2024

CVE-2024-4434 Scanner

CVE-2024-4434 scanner - SQL Injection vulnerability in LearnPress WordPress LMS Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-4434
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
LearnPress – WordPress LMS Plugin for Create and Sell Online Coursesby thimpress
0
learnpressby thimpress
4.2.6.5
Updated Sep 10, 2026View on NVD →
Detail

The LearnPress WordPress LMS Plugin is a popular learning management system plugin used by educators and institutions to create and manage online courses on WordPress websites. It enables users to create courses, lessons, and quizzes and track student progress. The plugin is widely used due to its comprehensive features and ease of use. However, like many plugins, it can be vulnerable to security issues if not properly managed and updated. Ensuring the security of the LearnPress plugin is crucial to protect sensitive educational data and user information.

The LearnPress WordPress LMS Plugin up to version 4.2.6.5 is susceptible to a time-based SQL Injection vulnerability. This vulnerability exists due to insufficient escaping on the user-supplied 'term_id' parameter. Attackers can exploit this flaw to inject malicious SQL queries, potentially leading to unauthorized access to sensitive information. This type of vulnerability can have severe implications for the security of the database and the overall application.

The SQL Injection vulnerability in the LearnPress WordPress LMS Plugin is located in the 'term_id' parameter used in an SQL query. An attacker can manipulate this parameter to inject additional SQL commands. Specifically, the lack of proper escaping and preparation allows for time-based SQL Injection, where the attacker can use SQL functions like SLEEP to delay responses and infer the existence of certain conditions. This can lead to the extraction of sensitive information from the database, including user data and administrative credentials.

Exploitation of this SQL Injection vulnerability can lead to severe security breaches. Attackers can gain unauthorized access to sensitive information stored in the database, such as user credentials, personal data, and course information. In some cases, attackers can manipulate the database to create, modify, or delete records, potentially disrupting the educational services provided by the platform. Additionally, the compromised data can be used for further attacks, including identity theft and targeted phishing campaigns.

Join the S4E platform to ensure the security of your digital assets with comprehensive vulnerability scanning and reporting. By using our platform, you can stay ahead of potential threats and secure your applications against various vulnerabilities, including SQL Injection. Our easy-to-use interface and detailed reports help you understand and remediate security issues quickly. Protect your users' data and maintain the integrity of your online services by becoming a member today.

References:

Solution Advice
  • Update the LearnPress WordPress LMS Plugin to version 4.2.6.6 or higher.
  • Implement proper input validation and escaping for all user-supplied parameters.
  • Regularly review and update your security measures to protect against SQL Injection and other vulnerabilities.
  • Consider using web application firewalls (WAF) to detect and block malicious requests.
  • Conduct regular security audits and penetration tests to identify and fix vulnerabilities promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-4434 scanner - SQL Injection vulnerability in LearnPress WordPress LMS Plugin | S4E