The LearnPress WordPress plugin before 4.1.7.2...
High severity
Unreviewed
Published
Oct 31, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Oct 31, 2022
Published to the GitHub Advisory Database
Oct 31, 2022
Last updated
Jan 30, 2023
The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticated users, which could lead to PHP Object Injection when a suitable gadget is present, leadint to remote code execution (RCE). To successfully exploit this vulnerability attackers must have knowledge of the site secrets, allowing them to generate a valid hash via the wp_hash() function.
References