CVE-2023-6223: LearnPress <= 4.2.5.7 - Insecure Direct Object Reference to Information Disclosure
The LearnPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.5.7 via the /wp-json/lp/v1/profile/course-tab REST API due to missing validation on the 'userID' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the details of another user's course progress.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6223?
CVE-2023-6223 has been classified as a high severity vulnerability due to the potential for authenticated attackers to exploit it.
How do I fix CVE-2023-6223?
To fix CVE-2023-6223, update the LearnPress plugin to version 4.2.5.8 or later.
What type of vulnerability is CVE-2023-6223?
CVE-2023-6223 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
Who is affected by CVE-2023-6223?
Any users of the LearnPress plugin for WordPress running versions up to and including 4.2.5.7 are affected by CVE-2023-6223.
Can CVE-2023-6223 be exploited remotely?
CVE-2023-6223 requires authenticated access, thus it can be exploited by authenticated users but not remotely by unauthenticated attackers.