CVE-2026-77823 | ThimPress LearnPress Plugin up to 4.4.4 on WordPress CSV Export execute orderby sql injection
A vulnerability categorized as problematic has been discovered in ThimPress LearnPress Plugin up to 4.4.4 on WordPress. This impacts the function LP_Order::handle_params_query_list_orders/DataBase::execute of the component CSV Export. Such manipulation of the argument orderby leads to sql injection.
This vulnerability is listed as CVE-2026-77823. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More