
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-3360 affects the LearnPress WordPress plugin versions before 4.1.7.2. The vulnerability was discovered and disclosed on October 5, 2022. The issue exists in a REST API endpoint that is accessible to unauthenticated users, where the plugin unsafely unserializes user input (WPScan, NVD).
The vulnerability is classified as a PHP Object Injection vulnerability with a CVSS score of 6.5 (medium). The issue stems from unsafe unserialization of user input in a REST API endpoint that is accessible to unauthenticated users. To successfully exploit this vulnerability, attackers must have knowledge of the site secrets to generate a valid hash via the wp_hash() function (WPScan).
If successfully exploited, this vulnerability could lead to PHP Object Injection when a suitable gadget is present, potentially resulting in remote code execution (RCE) on the affected system (WPScan).
The vulnerability requires an attacker to have knowledge of the site secrets to generate a valid hash using wp_hash() function. A proof of concept exists demonstrating the exploitation through a POST request to /wp-json/lp/v1/widgets/api endpoint (WPScan).
The vulnerability has been fixed in LearnPress version 4.1.7.2. Users are advised to update to this version or later to mitigate the risk (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."