LearnPress – WordPress LMS Plugin For Create And Sell Online Courses - SQLi (CVE-2024-8529)
Description
The LearnPress – WordPress LMS Plugin For Create And Sell Online Courses plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
psychologyCrowdSec Analysis
CVE-2024-8529 is a critical SQL injection vulnerability in the LearnPress WordPress LMS Plugin, affecting all versions up to and including 4.2.7. This flaw allows unauthenticated attackers to exploit the 'c_fields' parameter in the /wp-json/lp/v1/courses/archive-course REST API endpoint, enabling them to execute arbitrary SQL queries. Successful exploitation could lead to the extraction of sensitive database information, data manipulation, or even full compromise of the affected WordPress site.
CrowdSec has been tracking this vulnerability and its exploits since 17th of June 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2024-8529 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers exploit the /wp-json/learnpress/v1/courses REST API endpoint by injecting SQL commands via the c_fields parameter, enabling unauthenticated extraction of sensitive database information from vulnerable LearnPress installations.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2024-09-12 |
| Rule Released | 2026-06-17 |