LearnPress <= 3.2.6.8 - Privilege Escalation via accept-to-be-teacher action parameter

2020-04-20 00:00
Ram

Vulnerability Overview

The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.

Technical Analysis

REMEDIATION: Update to version 3.2.6.9, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C