Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor, create new pages or change the status of any existing post or page. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.9 or latest
References
https://www.wordfence.com/blog/2020/04/high-severity-vulnerabilities-patched-in-learnpress/
https://www.exploit-db.com/exploits/50138
https://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html
Related Vulnerabilities
WordPress Plugin AccessPress Social Icons Cross-Site Scripting (1.6.6)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5340)
WordPress Plugin Portfolio Gallery-Photo Gallery Cross-Site Scripting (1.5.7)
MongoDb CVE-2024-7553 Vulnerability (CVE-2024-7553)
WordPress Plugin Wordpress Forms Multiple Vulnerabilities (0.2.7.1)