LearnPress <= 3.2.6.8 - Authenticated Page Creation and Status Modification
2020-04-19 00:00
RamStrategic Overview
StatusPatched in 3.2.6.9
Affected Version
<= 3.2.6.8CVSS7.1High
CVE
CVE-2020-11510Vulnerability Overview
Versions below 3.2.6.9 allow an attacker to publish or trash any existing post or page, or even set it to a nonexistent status, at which point it would no longer appear on the site or be accessible from wp-admin, and could only be recovered by modifying its status in the database.
Technical Analysis
REMEDIATION: Update to version 3.2.6.9, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C