Description
WordPress Plugin LifterLMS-WP LMS for eLearning, Online Courses, & Quizzes is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access other student grades/answers. WordPress Plugin LifterLMS-WP LMS for eLearning, Online Courses, & Quizzes version 4.21.1 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 4.21.2 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:D45BB744-4A0D-4AF0-AA16-71F7E3EA6E00
https://plugins.svn.wordpress.org/lifterlms/trunk/readme.txt
Related Vulnerabilities
Roundcube Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-19205)
Apache HTTP Server Session Fixation Vulnerability (CVE-2018-17199)
WordPress Plugin Katalyst TimThumb 'timthumb.php' Arbitrary File Upload (1.0)
WordPress Plugin WP Airbnb Review Slider SQL Injection (3.2)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-15929)