Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ LearnPress: 75,000 WordPress Websites at Risk from Critical Vulnerabilities

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š LearnPress: 75,000 WordPress Websites at Risk from Critical Vulnerabilities


๐Ÿ’ก Newskategorie: Hacking
๐Ÿ”— Quelle: blackhatethicalhacking.com

LearnPress: 75,000 WordPress Websites at Risk from Critical Vulnerabilities

Premium Content

Patreon

Subscribe to Patreon to watch this episode.

Reading Time: 3 Minutes

LearnPress, a popular WordPress plugin for creating and selling online courses, has been found to contain multiple critical-severity flaws that were discovered by PatchStack.

Unfortunately, the plugin was found to contain multiple critical-severity vulnerabilities that were discovered by PatchStack, including pre-auth SQL injection and local file inclusion. These vulnerabilities can expose sensitive information, allow data modification, and enable arbitrary code execution. These vulnerabilities can expose sensitive information, allow data modification, and enable arbitrary code execution.

These vulnerabilities were discovered between November 30 and December 2, 2022 and reported to the software vendor.

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Update available, 25% applied.

The plugin is used by over 100,000 active websites and was reported to the software vendor on December 2, 2022. The vendor fixed the issues on December 20, 2022 with the release of LearnPress version 4.2.0.
However, according to statistics from WordPress.org, only 25% of users have applied the update, leaving 75,000 websites at risk of exploitation.

LearnPress versions on active installationsLearnPress versions on active installationsย (WordPress)

The vulnerabilities could expose credentials, authorization tokens, and API keys, leading to further compromise, which can have serious repercussions.

The 3 Vulnerabilitiesย 

The first vulnerability, CVE-2022-47615, is an unauthenticated local file inclusion flaw that allows attackers to display the contents of local files stored on the web server. The second vulnerability, CVE-2022-45808, is an unauthenticated SQL injection that can potentially lead to sensitive information disclosure, data modification, and arbitrary code execution. The third vulnerability, CVE-2022-45820, is an authenticated SQL injection flaw in two shortcodes of the plugin.

ย 

SQL injection example

SQL injection exampleย (PatchStack)

The vendor has fixed these issues by introducing an allowlist and sanitization of the vulnerable variables or removing the ability to include templates in user input. Website owners relying on LearnPress are advised to either upgrade to version 4.2.0 or disable the plugin until they can apply the available security update.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: [email protected]

Source: bleepingcomputer.com

Source Link

Merch
The post LearnPress: 75,000 WordPress Websites at Risk from Critical Vulnerabilities first appeared on Black Hat Ethical Hacking. ...



๐Ÿ“Œ LearnPress: 75,000 WordPress Websites at Risk from Critical Vulnerabilities


๐Ÿ“ˆ 63.64 Punkte

๐Ÿ“Œ Experts Comments On Bugs In WordPress plugins LearnPress, LearnDash, And LifterLMS For Online Courses Let Students Cheat


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ Flaws in Ninja Forms, LearnPress Plugins Exposed WordPress Sites to Attacks


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ CVE-2022-3360 | LearnPress Plugin prior 4.1.7.2 on WordPress REST API Endpoint wp_hash deserialization


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ CVE-2022-45808 | LearnPress Plugin up to 4.1.7.3.2 on WordPress sql injection


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ CVE-2023-6223 | LearnPress Plugin up to 4.2.5.7 on WordPress resource injection (ID 3013957)


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ CVE-2023-6567 | LearnPress Plugin up to 4.2.5.7 on WordPress order_by sql injection (ID 3013957)


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ CVE-2023-6634 | LearnPress Plugin up to 4.2.5.7 on WordPress command injection (ID 3013957)


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ CVE-2023-5558 | LearnPress Plugin up to 4.2.5.4 on WordPress cross site scripting


๐Ÿ“ˆ 31.2 Punkte

๐Ÿ“Œ Over a million websites could be at risk from critical WordPress gallery plugin flaw


๐Ÿ“ˆ 27.54 Punkte

๐Ÿ“Œ Thousands of websites at risk from critical WordPress commenting plugin vulnerability


๐Ÿ“ˆ 27.54 Punkte

๐Ÿ“Œ WordPress Websites at Risk โ€“ Hackers Exploit Critical Flaw in Essential Addons for Elementor


๐Ÿ“ˆ 27.54 Punkte

๐Ÿ“Œ LearnPress up to 3.0.x sql injection [CVE-2018-16175]


๐Ÿ“ˆ 26.32 Punkte

๐Ÿ“Œ LearnPress up to 3.0.x Open Redirect [CVE-2018-16174]


๐Ÿ“ˆ 26.32 Punkte

๐Ÿ“Œ LearnPress up to 3.0.x cross site scripting [CVE-2018-16173]


๐Ÿ“ˆ 26.32 Punkte

๐Ÿ“Œ Medium CVE-2020-6010: Thimpress Learnpress


๐Ÿ“ˆ 26.32 Punkte

๐Ÿ“Œ WordPress Captcha Plugin Contains Backdoor- 300,000 Websites at Risk


๐Ÿ“ˆ 25.97 Punkte

๐Ÿ“Œ Critical bugs in WordPress plugins InfiniteWP, WP Time Capsule expose 320,000 websites to attack


๐Ÿ“ˆ 25.03 Punkte

๐Ÿ“Œ Critical RCE Bug in WordPress Plugin Let Hackers Gain Admin Access on 200,000 Websites


๐Ÿ“ˆ 25.03 Punkte

๐Ÿ“Œ Critical flaw found in WordPress plugin used on over 300,000 websites


๐Ÿ“ˆ 25.03 Punkte

๐Ÿ“Œ Over 15,000 Websites were Hacked to Redirect Visitors to Fake Q&A Websites


๐Ÿ“ˆ 22.39 Punkte

๐Ÿ“Œ WordPress plugin vulnerability puts two million websites at risk


๐Ÿ“ˆ 21.05 Punkte

๐Ÿ“Œ Invision Community Vulnerabilities Risk E-Commerce Websites


๐Ÿ“ˆ 21.01 Punkte

๐Ÿ“Œ Critical Bug In Two WordPress Plugins Risked Over 320K Websites


๐Ÿ“ˆ 20.11 Punkte

๐Ÿ“Œ Critical WordPress Plugin Bug Can Lock Admins Out of Websites


๐Ÿ“ˆ 20.11 Punkte

๐Ÿ“Œ Critical Flaws in WordPress Houzez Theme Exploited to Hijack Websites


๐Ÿ“ˆ 20.11 Punkte

๐Ÿ“Œ WordPress Plug-in Used in 1M+ Websites Patched to Close Critical Bug


๐Ÿ“ˆ 20.11 Punkte

๐Ÿ“Œ WordPress Plugin Alert - Critical SQLi Vulnerability Threatens 200K+ Websites


๐Ÿ“ˆ 20.11 Punkte

๐Ÿ“Œ Critical flaw in WooCommerce can be used to compromise WordPress websites


๐Ÿ“ˆ 20.11 Punkte

๐Ÿ“Œ Mitigating Risk and High-Risk Vulnerabilities in Unsupported Operating Systems: BlueKeep Edition


๐Ÿ“ˆ 19.72 Punkte

๐Ÿ“Œ Meanwhile Apple get 1,000,000,000,000 $ in bourse ...........


๐Ÿ“ˆ 19.7 Punkte

๐Ÿ“Œ Zahlen, bitte! 1.000.000.000.000 Euro fรผr "Made in Germany"


๐Ÿ“ˆ 19.7 Punkte

๐Ÿ“Œ 1.000.000.000.000 Euro fรผr "Made in Germany" | Zahlen, bitte!


๐Ÿ“ˆ 19.7 Punkte

๐Ÿ“Œ AIโ€™s Secret Future Blueprint LEAKED: How Brain Power Is The $25,000,000,000,000 Answer ...


๐Ÿ“ˆ 19.7 Punkte











matomo