Description
WordPress Plugin WP Learn Manager is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create/edit arbitrary User Fields. WordPress Plugin WP Learn Manager version 1.1.4 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 1.1.5 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:56031D26-4B15-47D7-9FA3-135299D591DA
https://plugins.svn.wordpress.org/learn-manager/trunk/readme.txt
Related Vulnerabilities
MySQL CVE-2020-14869 Vulnerability (CVE-2020-14869)
MySQL CVE-2024-20973 Vulnerability (CVE-2024-20973)
OpenSSL Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-0778)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.13)
Magento Improper Authorization Vulnerability (CVE-2021-21022)