PT-2022-7084 · WordPress · Learnpress
Rafie Muhammad
·
Published
2022-12-02
·
Updated
2023-02-02
·
CVE-2022-47615
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LearnPress – WordPress LMS Plugin versions <= 4.1.7.3.2
Description
The issue is related to a Local File Inclusion vulnerability. It concerns the
list courses() function of the LearnPress plugin in the WordPress content management system. The vulnerability is associated with insufficient restrictions on the directory path name when processing variables such as template pagination path, template path, and template path item. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.Recommendations
For LearnPress – WordPress LMS Plugin versions <= 4.1.7.3.2, consider disabling the
list courses() function as a temporary workaround until a patch is available. Restrict access to the variables template pagination path, template path, and template path item to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Learnpress