Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor, create new pages or change the status of any existing post or page. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.9 or latest
References
https://www.wordfence.com/blog/2020/04/high-severity-vulnerabilities-patched-in-learnpress/
https://www.exploit-db.com/exploits/50138
https://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html
Related Vulnerabilities
Plone CMS Other Vulnerability (CVE-2006-4247)
WordPress Plugin Post Grid, List for WordPress-Content Views Cross-Site Scripting (1.9.0)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2154)
WordPress Plugin Ad Manager by WD-Advanced Ad Manager Multiple Vulnerabilities (1.0.11)