CVE-2021-24951

Publication date

2021-12-13 10:41:26

Family

WPScan

State

PUBLISHED

Description

The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues