CVE-2023-6634

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:44

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset/3013957/learnpress - Third Party Advisory () https://plugins.trac.wordpress.org/changeset/3013957/learnpress - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/21291ed7-cdc0-4698-9ec4-8417160845ed?source=cve - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/21291ed7-cdc0-4698-9ec4-8417160845ed?source=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.1

17 Jan 2024, 20:44

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset/3013957/learnpress - () https://plugins.trac.wordpress.org/changeset/3013957/learnpress - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/21291ed7-cdc0-4698-9ec4-8417160845ed?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/21291ed7-cdc0-4698-9ec4-8417160845ed?source=cve - Third Party Advisory
First Time Thimpress
Thimpress learnpress
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:thimpress:learnpress:*:*:*:*:*:wordpress:*:*
CWE CWE-77

11 Jan 2024, 13:57

Type Values Removed Values Added
Summary
  • (es) El complemento LearnPress para WordPress es vulnerable a la inyección de comandos en todas las versiones hasta la 4.2.5.7 incluida a través de la función get_content. Esto se debe a que el complemento utiliza la función call_user_func con la entrada del usuario. Esto hace posible que atacantes no autenticados ejecuten cualquier función pública con un parámetro, lo que podría resultar en la ejecución remota de código.

11 Jan 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-11 09:15

Updated : 2024-11-21 08:44


NVD link : CVE-2023-6634

Mitre link : CVE-2023-6634

CVE.ORG link : CVE-2023-6634


JSON object : View

Products Affected

thimpress

  • learnpress
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')