Update the WordPress LearnPress plugin to the latest available version (at least 4.2.0).
Rafie Muhammad (Patchstack) discovered and reported this SQL Injection vulnerability in WordPress LearnPress Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information and creating new administrator accounts. This vulnerability has been fixed in version 4.2.0.
Local File Inclusion
20.01.2023
Unauthenticated SQL Injection Vulnerability
20.01.2023
Unauthenticated PHP Object Injection vulnerability
05.10.2022
Reflected CrossSite Scripting (XSS) vulnerability
21.06.2022
Reflected CrossSite Scripting (XSS) vulnerability
16.03.2022