LearnPress <= 3.2.6.8 - Privilege Escalation via accept-to-be-teacher action parameter
2020-04-20 00:00
RamStrategic Overview
StatusPatched in 3.2.6.9
Affected Version
<= 3.2.6.8CVSS8.1High
CVE
CVE-2020-11511Vulnerability Overview
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
Technical Analysis
REMEDIATION: Update to version 3.2.6.9, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C