LearnPress <= 3.2.6.6 - Privilege Escalation
2020-03-16 00:00
AnonymousStrategic Overview
StatusPatched in 3.2.6.8
Affected Version
<= 3.2.6.6CVSS7.1High
CVE
CVE-2020-7916Vulnerability Overview
be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered user to assign itself the teacher role via the wp-admin/admin-ajax.php?action=learnpress_be_teacher URI without any additional permission checks. Therefore, any user can change its role to an instructor/teacher and gain access to otherwise restricted data.
Technical Analysis
REMEDIATION: Update to version 3.2.6.8, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C