Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently rename an arbitrary image file. WordPress Plugin LearnPress-WordPress LMS version 4.1.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.1.5 or latest
References
https://bozogullarindan.com/en/2022/01/wordpress-learnpress-plugin-4.1.4.1-arbitrary-image-renaming/
Related Vulnerabilities
WordPress Plugin WP-DownloadManager Cross-Site Request Forgery (1.60)
WordPress Plugin Poll Maker SQL Injection (3.2.0)
WordPress Plugin Spider Calendar Cross-Site Scripting (1.1.0)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Unspecified Vulnerability (4.8)
WordPress Plugin Magn WP Drag and Drop Upload Arbitrary File Upload (1.1.4)