Description
WordPress Plugin WP Courses LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access restricted content via the REST API. WordPress Plugin WP Courses LMS version 2.0.28 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.29 or latest
References
Related Vulnerabilities
WordPress Plugin CMS Commander Client PHP Object Injection (2.21)
WordPress Plugin Chained Quiz Multiple Cross-Site Scripting Vulnerabilities (0.9.8)
WordPress Plugin Custom Fields Search by BestWebSoft Cross-Site Scripting (1.3.1)
WordPress Plugin Easing Slider Multiple Cross-Site Scripting Vulnerabilities (2.2.0.6)
WordPress Plugin Translate WordPress-Google Language Translator Cross-Site Scripting (6.0.11)