Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor, create new pages or change the status of any existing post or page. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.9 or latest
References
https://www.wordfence.com/blog/2020/04/high-severity-vulnerabilities-patched-in-learnpress/
https://www.exploit-db.com/exploits/50138
https://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2007-0540)
WordPress Plugin WP-Members Membership Cross-Site Scripting (3.1.4.2)
WordPress Plugin Count per Day Search Bar Cross-Site Scripting (3.2.2)
WordPress Plugin Two-Factor Authentication-Clockwork SMS Cross-Site Scripting (1.0.3)
WordPress Plugin GD Star Rating 'tpl_section' Parameter Cross-Site Scripting (1.9.16)