Description
WordPress Plugin LifterLMS-WP LMS for eLearning, Online Courses, & Quizzes is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's options. WordPress Plugin LifterLMS-WP LMS for eLearning, Online Courses, & Quizzes version 3.34.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.35.0 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-lifterlms-plugin/
https://plugins.svn.wordpress.org/lifterlms/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WonderPlugin Audio Player Multiple Vulnerabilities (2.0)
WordPress Plugin Dynamic Content for Elementor Remote Code Execution (1.9.5.6)
WordPress Plugin Developer Formatter Cross-Site Request Forgery (2012.0.1.39)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Security Bypass (3.10.15)