PT-2024-31154 · WordPress · Learnpress
1337_Wannabe
+1
·
Published
2024-04-08
·
Updated
2025-01-16
·
CVE-2024-4444
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LearnPress – WordPress LMS Plugin plugin for WordPress versions up to, and including, 4.2.6.5
Description
The issue is due to missing checks in the
create account function in the checkout, making it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.Recommendations
For versions up to, and including, 4.2.6.5, update to a version that includes a fix for the missing checks in the
create account function to prevent unauthorized user registration.
As a temporary workaround, consider disabling the create account function in the checkout until a patch is available.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Learnpress