Description
WordPress Plugin LifterLMS-WP LMS for eLearning, Online Courses, & Quizzes is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's options. WordPress Plugin LifterLMS-WP LMS for eLearning, Online Courses, & Quizzes version 3.34.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.35.0 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-lifterlms-plugin/
https://plugins.svn.wordpress.org/lifterlms/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Super Forms-Drag & Drop Form Builder Arbitrary File Upload (4.9.700)
Oracle JRE CVE-2023-21968 Vulnerability (CVE-2023-21968)
Moodle Improper Input Validation Vulnerability (CVE-2006-4935)
WordPress Configuration Vulnerability (CVE-2009-2335)
WordPress Plugin WP Code Highlight.js Cross-Site Request Forgery (0.6.2)