First published: Tue Jul 27 2021(Updated: )
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thimpress Learnpress | <3.2.6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2020-11511.
The severity level of CVE-2020-11511 is high with a score of 8.1.
The affected software for CVE-2020-11511 is the LearnPress plugin before version 3.2.6.9 for WordPress.
An attacker can exploit CVE-2020-11511 by using the accept-to-be-teacher action parameter to escalate the privileges of any user to LP Instructor.
You can find more information about CVE-2020-11511 at the following references: - http://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html - https://cwe.mitre.org/data/definitions/862.html - https://wordpress.org/plugins/learnpress/#developers