CVE-2020-6010

HIGH

LearnPress <3.2.6.7 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-6010. PoCs published by nhattruong, h00die, Omri Herscovici, Sagi Tzadik, nhattruong, including Metasploit module auxiliary/scanner/http/wp_learnpress_sqli.

AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in WordPress Plugin LearnPress versions prior to 3.2.6.8. The exploit manipulates the 'current_items[]' parameter in an AJAX request to inject a SQL payload, causing a delay via the 'sleep' function.

Description

LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection

Exploits (2)

exploitdb WORKING POC
by nhattruong · textwebappsphp
https://www.exploit-db.com/exploits/50137

This exploit demonstrates an authenticated SQL injection vulnerability in WordPress Plugin LearnPress versions prior to 3.2.6.8. The exploit manipulates the 'current_items[]' parameter in an AJAX request to inject a SQL payload, causing a delay via the 'sleep' function.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin LearnPress < 3.2.6.8
Auth required
Prerequisites: Valid WordPress credentials · LearnPress plugin version < 3.2.6.8
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by h00die, Omri Herscovici, Sagi Tzadik, nhattruong · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_learnpress_sqli.rb

This Metasploit module exploits an authenticated SQL injection vulnerability in WordPress LearnPress plugin versions prior to 3.2.6.8. It allows enumeration of user credentials via the 'current_items' parameter in the post-new.php page.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WordPress LearnPress plugin < 3.2.6.8
Auth required
Prerequisites: Valid WordPress credentials · LearnPress plugin version < 3.2.6.8
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.5017
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
thimpress/learnpress < 3.2.6.7
Published Apr 30, 2020
Tracked Since Feb 18, 2026