info:
LearnDash v3.1.6 - *Security Update*
Today we released LearnDash v3.1.6 which includes an important security patch. We encourage you to update LearnDash as soon as possible.
If you're in a hurry, here is a quick summary:
- We received a report of a secondary SQL vulnerability in LearnDash related to the PayPal IPN.
- While this category of vulnerability is a high-priority issue (and thus why you are receiving this message), it is not possible for someone to actually do anything malicious due to how data is stored in LearnDash.
- The issue was reviewed, fixed, and tested hours after being reported, and an update has been pushed out. Update to LearnDash v3.1.6 for the fix.
If you are interested in a little more detail we have the following list of FAQs.
What can happen if someone takes advantage of this issue?
In short: not much. The SQL data injection can occur, but it is not possible for anyone to actually interact with it because of how LearnDash stores the data related to the PayPal IPN. Nonetheless, you should still make updating to the latest version a priority.
When was this issue reported?
We received a report today (31-March-2020). After review, we worked on a fix, tested it, and pushed out the update.