CVE-2022-45820
SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
- Affected products
- Learnpress
- Thimpress Learnpress
- ≤ 4.1.7.3.2
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 1.0% (61th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2023-01-24
- Attack patterns
- CAPEC-66
- Entry point
- action request body
- Path
- /wp-admin/admin-ajax.php
Fix
Update to 4.2.0 or higher version.
CVE-2022-45820 at NVD
1 known exploit for CVE-2022-45820
Proof-of-concept code and exploit modules indexed by Sploitus