HIGH
LearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST API
Published Oct 31, 2022
8.1
HIGHCVSS 3.1
EPSS 2.01%
Description
The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowledge of the site secrets, allowing them to generate a valid hash via the wp_hash() function.
Affected products
- Vendor n/a Product LearnPress – WordPress LMS Plugin Defaultn/a
- Version 4.1.7.2StatusaffectedConstraints<4.1.7.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | LearnPress – WordPress LMS Plugin | n/a |
|
- < 4.1.7.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42743 Advisory
- https://wpscan.com/vulnerability/acea7a54-a964-4127-a93f-f38f883074e3 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42743 | Advisory | |
| https://wpscan.com/vulnerability/acea7a54-a964-4127-a93f-f38f883074e3 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Oct 31, 2022
Updated May 6, 2025
Reserved Sep 29, 2022
Link CVE-2022-3360
CISA Vulnrichment
Updated May 6, 2025
ENISA EUVD
EUVD-2022-42743 Assigner WPScan
Published Oct 31, 2022
Updated May 6, 2025
Exploited since n/a
Link EUVD-2022-42743