Description
WordPress Plugin LMS by LifterLMS-Online Course, Membership & Learning Management System for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's options. WordPress Plugin LMS by LifterLMS-Online Course, Membership & Learning Management System for WordPress version 3.34.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.35.0 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-lifterlms-plugin/
https://plugins.svn.wordpress.org/lifterlms/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin ALO EasyMail Newsletter Cross-Site Request Forgery (2.9.2)
WordPress Plugin Woocommerce Product Designer Arbitrary File Upload (3.0.3)
WordPress Plugin TinyMCE Color Picker Multiple Vulnerabilities (1.1)
WordPress Plugin Widgets for SiteOrigin Security Bypass (1.4.2)
WordPress Plugin Gmedia Photo Gallery Cross-Site Scripting (0.9.3)