← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 1, 2026 · 04:27via CVEFeed

CVE-2026-77823 - LearnPress = 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

Brief

CVE ID : CVE-2026-77823

Published : Sept. 1, 2026, 4:27 a. m.

  • 48 minutes ago

Description : The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.

  • 4.

This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the LP_Order::handle_params_query_list_orders() and DataBase::execute() functions — only the literal values 'date' and 'title' are normalized, while any other attacker-controlled string is assigned directly to the filter's order_by property and concatenated into the ORDER BY clause without $wpdb-prepare() or an identifier whitelist.

Read more on CVEFeed