Description
WordPress Plugin LearnPress-WordPress LMS is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the role of all users to Instructor, create new pages or change the status of any existing post or page. WordPress Plugin LearnPress-WordPress LMS version 3.2.6.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.6.9 or latest
References
https://www.wordfence.com/blog/2020/04/high-severity-vulnerabilities-patched-in-learnpress/
https://www.exploit-db.com/exploits/50138
https://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html
Related Vulnerabilities
WordPress Plugin Subscribe Sidebar by Blubrry Cross-Site Scripting (1.3.1)
WordPress Plugin Easy Social Icons Multiple Vulnerabilities (1.2.2)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall SQL Injection (3.8.7)
WordPress Plugin RokIntroScroller Multiple Vulnerabilities (1.8)
WordPress Plugin Premmerce Variation Swatches for WooCommerce Security Bypass (1.0)