POC Wordpress SQL Injection vulnerability LearnPress REST API endpoint # CVE-2024-8522 - Contact <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a> Tool is available for purchase.
POC Wordpress SQL Injection vulnerability LearnPress REST API endpoint Contact: <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a>
# With SQJ Injection, a new admin user can be created and the target website can be access full system.
Contact: <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a>
🚨🚨CVE-2024-8522 (CVSS: 10) : LearnPress - WordPress LMS Plugin Unauthenticated SQL Injection
⚠️The vulnerability resides in the LearnPress REST API endpoint, specifically in the handling of the ‘c_only_fields’ parameter. Insufficient escaping and inadequate preparation of SQL queries allow attackers to inject malicious SQL code.
ZoomEye Dork👉app:"WordPress LearnPress"
Contact: <a href="https://t.me/bl4ckhatx" target="_blank">@bl4ckhatx</a>
https://www.zoomeye.hk/searchResult?q=app%3A%22WordPress%20LearnPress%22&from=5o6o54m5MjQwOTEyMDM=
[4.0K] /data/pocs/9de3f0b13b7563c5a6af3a51604ed4308ff6f422
└── [1011] README.md
0 directories, 1 file