PT-2021-9421 · WordPress · Learnpress

Ramuel Gall

·

Published

2021-07-27

·

Updated

2022-12-09

·

CVE-2020-11511

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LearnPress plugin versions prior to 3.2.6.9 for WordPress
Description The issue allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
Recommendations For versions prior to 3.2.6.9, update to version 3.2.6.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the accept-to-be-teacher action parameter until the update is applied.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-11511

Affected Products

Learnpress