The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to extract basic information about website users, including their emails
References
Configurations
History
21 Nov 2024, 09:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.8/inc/jwt/rest-api/version1/class-lp-rest-users-v1-controller.php#L130 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/122b75d2-e882-45b9-baf1-acf847f8d60a?source=cve - Third Party Advisory |
11 Jun 2024, 17:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.8/inc/jwt/rest-api/version1/class-lp-rest-users-v1-controller.php#L130 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/122b75d2-e882-45b9-baf1-acf847f8d60a?source=cve - Third Party Advisory | |
First Time |
Thimpress
Thimpress learnpress |
|
Summary |
|
|
CPE | cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo |
05 Jun 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-05 03:15
Updated : 2024-11-21 09:47
NVD link : CVE-2024-5483
Mitre link : CVE-2024-5483
CVE.ORG link : CVE-2024-5483
JSON object : View
Products Affected
thimpress
- learnpress
CWE