Description
WordPress Plugin Learning Courses is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Learning Courses version 4.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.7.1 or latest
References
Related Vulnerabilities
WordPress Plugin Active Extra Fields Cross-Site Scripting (1.0.1)
Apache Traffic Server Exposure of Resource to Wrong Sphere Vulnerability (CVE-2018-8040)
WordPress Plugin RestroPress-Online Food Ordering System Cross-Site Request Forgery (2.8.2)
WordPress Plugin WP Photo Album Plus Cross-Site Scripting (5.0.2)
WordPress Plugin WP Booking System Cross-Site Scripting (1.3.3)