Description
WordPress Plugin Academy LMS-eLearning and online course solution for WordPress is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Academy LMS-eLearning and online course solution for WordPress version 1.9.19 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.9.20 or latest
References
Related Vulnerabilities
WordPress Plugin Advanced User Registration and Management Cross-Site Scripting (2.3.5)
MySQL CVE-2022-39403 Vulnerability (CVE-2022-39403)
MediaWiki Other Vulnerability (CVE-2013-2114)
WordPress Plugin YouTube Video Inserter Cross-Site Scripting (1.2.1.0)
concrete5 Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-13790)