Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.7 or latest
References
Related Vulnerabilities
PHPFusion Multiple SQL Injection Vulnerabilities (CVE-2014-8596)
WordPress Plugin Slimstat Analytics Cross-Site Scripting (5.0.4)
WordPress Plugin Activity Log Information Disclosure (2.2.12)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.18)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-30179)