POC Wordpress SQL Injection vulnerability LearnPress REST API endpoint # CVE-2024-8522 - Contact <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a> Tool is available for purchase.
POC Wordpress SQL Injection vulnerability LearnPress REST API endpoint Contact: <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a>
# With SQJ Injection, a new admin user can be created and the target website can be access full system.
Contact: <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a>
🚨🚨CVE-2024-8522 (CVSS: 10) : LearnPress - WordPress LMS Plugin Unauthenticated SQL Injection
⚠️The vulnerability resides in the LearnPress REST API endpoint, specifically in the handling of the ‘c_only_fields’ parameter. Insufficient escaping and inadequate preparation of SQL queries allow attackers to inject malicious SQL code.
ZoomEye Dork👉app:"WordPress LearnPress"
Contact: <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a>
https://www.zoomeye.hk/searchResult?q=app%3A%22WordPress%20LearnPress%22&from=5o6o54m5MjQwOTEyMDM=
登录后查看神龙缓存的 POC 文件快照
登录查看