Description
WordPress Plugin Academy LMS-eLearning and online course solution for WordPress is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Academy LMS-eLearning and online course solution for WordPress version 1.9.19 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.20 or latest
References
Related Vulnerabilities
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36155)
WordPress Plugin Gallery for Social Photo Cross-Site Request Forgery (1.0.0.27)
WordPress Plugin Vertical SlideShow Arbitrary File Upload (2.3)
WordPress Plugin Top 10-Popular posts for WordPress SQL Injection (2.4.3)