CVE-2020-11511: High severity thimpress learnpress vulnerability
The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP Instructor via the accept-to-be-teacher action parameter.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-11511.
What is the severity level of CVE-2020-11511?
The severity level of CVE-2020-11511 is high with a score of 8.1.
What is the affected software for CVE-2020-11511?
The affected software for CVE-2020-11511 is the LearnPress plugin before version 3.2.6.9 for WordPress.
How can an attacker exploit CVE-2020-11511?
An attacker can exploit CVE-2020-11511 by using the accept-to-be-teacher action parameter to escalate the privileges of any user to LP Instructor.
Where can I find more information about CVE-2020-11511?
You can find more information about CVE-2020-11511 at the following references: - http://packetstormsecurity.com/files/163538/WordPress-LearnPress-Privilege-Escalation.html - https://cwe.mitre.org/data/definitions/862.html - https://wordpress.org/plugins/learnpress/#developers