Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.7 or latest
References
Related Vulnerabilities
MySQL Other Vulnerability (CVE-2002-1376)
MySQL CVE-2019-2482 Vulnerability (CVE-2019-2482)
Microsoft SQL Server CVE-2023-36728 Vulnerability (CVE-2023-36728)
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-16107)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3835)