Description
WordPress Plugin WP Courses LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access restricted content via the REST API. WordPress Plugin WP Courses LMS version 2.0.28 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.29 or latest
References
Related Vulnerabilities
Plone CMS Missing Authentication for Critical Function Vulnerability (CVE-2020-35190)
MySQL CVE-2021-35622 Vulnerability (CVE-2021-35622)
MySQL CVE-2022-21304 Vulnerability (CVE-2022-21304)
WordPress Plugin Woody ad snippets-Insert Header Footer Code, AdSense Ads Security Bypass (2.2.5)
WordPress Plugin Kama Click Counter Cross-Site Scripting (3.4.9)