LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update

2024-07-08 20:01
Lucio Sá

Strategic Overview

Status
Patched in 1.8.2.2
Affected Version<= 1.8.2.1
CVSS5.4Medium
CVECVE-2024-5648
View all LearnDash LMS – Reports vulnerabilities

Vulnerability Overview

The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. wrld_set_configuration, wrld_exclude_settings_save, apply_time_tracking_settings, wp_ajax_wrld_gutenberg_block_visit, etc..) in all versions up to, and including, 1.8.2.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to update various plugin settings.

Technical Analysis

REMEDIATION: Update to version 1.8.2.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update (CVE-2024-5648)