Description
WordPress Plugin LearnDash LMS is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to reset arbitrary user passwords. WordPress Plugin LearnDash LMS version 4.6.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.6.0.1 or latest
References
Related Vulnerabilities
Joomla! Core 3.x.x Multiple Cross-Site Request Forgery Vulnerabilities (3.0.0 - 3.9.14)
Oracle Database Server CVE-2015-2655 Vulnerability (CVE-2015-2655)
Oracle Database Server CVE-2020-2518 Vulnerability (CVE-2020-2518)
WordPress Plugin WordPress Gallery-NextGEN Gallery Cross-Site Request Forgery (3.28)