Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently rename an arbitrary image file. WordPress Plugin LearnPress-WordPress LMS version 4.1.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.5 or latest
References
https://bozogullarindan.com/en/2022/01/wordpress-learnpress-plugin-4.1.4.1-arbitrary-image-renaming/
Related Vulnerabilities
WordPress Plugin Meow Gallery (+ Gallery Block) Security Bypass (4.1.9)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7951)
MySQL CVE-2016-0653 Vulnerability (CVE-2016-0653)
WordPress Plugin Advanced Order Export For WooCommerce Cross-Site Scripting (3.1.7)