# CVE-2024-8529: LearnPress – WordPress LMS Plugin For Create And Sell Online Courses - SQLi

> Live exploitation tracking for CVE-2024-8529 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2024-8529

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 10.0
- **Public exploit available:** Yes
- **Affected products:** ThimPress LearnPress – WordPress LMS Plugin For Create And Sell Online Courses
- **Weaknesses:** CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))
- **Tags:** wordpress, cms

## Description

The LearnPress – WordPress LMS Plugin For Create And Sell Online Courses plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

## CrowdSec analysis

[CVE-2024-8529](https://euvd.enisa.europa.eu/vulnerability/CVE-2024-8529) is a critical SQL injection vulnerability in the LearnPress WordPress LMS Plugin, affecting all versions up to and including 4.2.7. This flaw allows unauthenticated attackers to exploit the 'c_fields' parameter in the /wp-json/lp/v1/courses/archive-course REST API endpoint, enabling them to execute arbitrary SQL queries. Successful exploitation could lead to the extraction of sensitive database information, data manipulation, or even full compromise of the affected WordPress site.

CrowdSec has been tracking this vulnerability and its exploits since 17th of June 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2024-8529 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers exploit the `/wp-json/learnpress/v1/courses` REST API endpoint by injecting SQL commands via the `c_fields` parameter, enabling unauthenticated extraction of sensitive database information from vulnerable LearnPress installations.

## Timeline

- 2024-09-12: CVE Published. CVE-2024-8529 is published to NVD.
- 2026-06-17: Rule Released. CrowdSec releases a rule to detect CVE-2024-8529 exploitation attempts against the CrowdSec Network.

## References

- https://abrahack.com/posts/learnpress-sqli/
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-8529.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2024-8529) follows observed exploitation activity for CVE-2024-8529. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
