Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor, create new pages or change the status of any existing post or page. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.9 or latest
References
https://www.wordfence.com/blog/2020/04/high-severity-vulnerabilities-patched-in-learnpress/
https://www.exploit-db.com/exploits/50138
https://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html
Related Vulnerabilities
WordPress Plugin Grapefile File Sharing 'grapeupload.php' Arbitrary File Upload (1.1)
MongoDb Missing Authorization Vulnerability (CVE-2026-13078)
OpenSSL Cryptographic Issues Vulnerability (CVE-2014-3572)
MySQL CVE-2020-14809 Vulnerability (CVE-2020-14809)
WordPress Plugin Import and export users and customers Cross-Site Scripting (1.14.1.2)