Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.7 or latest
References
Related Vulnerabilities
MySQL CVE-2020-2814 Vulnerability (CVE-2020-2814)
WordPress Plugin HTML5 Lyrics Karaoke Player Cross-Site Scripting (1.06)
PostgreSQL Improper Access Control Vulnerability (CVE-2019-10127)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6212)
WordPress Plugin Rent-A-Car TimThumb Arbitrary File Upload (1.0)