Vulnerabilities > CVE-2020-11511 - Missing Authorization vulnerability in Thimpress Learnpress
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | CGI abuses |
NASL id | WORDPRESS_PLUGIN_LEARNPRESS_3_2_6_8.NASL |
description | The WordPress application running on the remote host has a version of the |
last seen | 2020-05-06 |
modified | 2020-05-01 |
plugin id | 136191 |
published | 2020-05-01 |
reporter | This script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/136191 |
title | WordPress Plugin 'LearnPress' < 3.2.6.8 Multiple Vulnerabilities |
code |
|
The Hacker News
id | THN:047CA924D8DECEDDC49DB26C77A3339B |
last seen | 2020-04-30 |
modified | 2020-04-30 |
published | 2020-04-30 |
reporter | The Hacker News |
source | https://thehackernews.com/2020/04/wordpress-lms-plugins.html |
title | Critical Bugs Found in 3 Popular e-Learning Plugins for WordPress Sites |
References
- http://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html
- https://cwe.mitre.org/data/definitions/862.html
- https://wordpress.org/plugins/learnpress/#developers
- https://www.wordfence.com/blog/2020/04/high-severity-vulnerabilities-patched-in-learnpress/
- http://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html
- https://www.wordfence.com/blog/2020/04/high-severity-vulnerabilities-patched-in-learnpress/
- https://wordpress.org/plugins/learnpress/#developers
- https://cwe.mitre.org/data/definitions/862.html