Exploitation Summary
EIP tracks 2 public exploits for CVE-2020-6010.
PoCs published by nhattruong, h00die, Omri Herscovici, Sagi Tzadik, nhattruong, including Metasploit module auxiliary/scanner/http/wp_learnpress_sqli.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in WordPress Plugin LearnPress versions prior to 3.2.6.8. The exploit manipulates the 'current_items[]' parameter in an AJAX request to inject a SQL payload, causing a delay via the 'sleep' function.
Description
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
Exploits (2)
This exploit demonstrates an authenticated SQL injection vulnerability in WordPress Plugin LearnPress versions prior to 3.2.6.8. The exploit manipulates the 'current_items[]' parameter in an AJAX request to inject a SQL payload, causing a delay via the 'sleep' function.
This Metasploit module exploits an authenticated SQL injection vulnerability in WordPress LearnPress plugin versions prior to 3.2.6.8. It allows enumeration of user credentials via the 'current_items' parameter in the post-new.php page.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H