CVE-2024-2115: LearnPress – WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is due to missing or incorrect nonce validation on the filterusers functions. This makes it possible for unauthenticated attackers to elevate their privileges to that of a teacher via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2115?
CVE-2024-2115 is classified as a high severity flaw due to its potential for unauthenticated privilege escalation.
How do I fix CVE-2024-2115?
To remediate CVE-2024-2115, update the LearnPress plugin to version 4.0.1 or later.
What types of attacks can exploit CVE-2024-2115?
CVE-2024-2115 can be exploited through Cross-Site Request Forgery attacks, allowing attackers to perform unauthorized actions.
Which versions of LearnPress are affected by CVE-2024-2115?
All versions of the LearnPress plugin prior to 4.0.1 are affected by CVE-2024-2115.
What is the impact of exploiting CVE-2024-2115?
Exploitation of CVE-2024-2115 can lead to unauthorized user account creation and modification of user settings.