CVE-2024-39642: WordPress LearnPress plugin <= 4.2.6.8.2 - Insecure Direct Object References (IDOR) vulnerability
Published Aug 13, 2024
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LearnPress: from n/a through 4.2.6.8.2.
Affected Software
2 affected components
thimpress LearnPress>=n/a<4.2.6.8.2
WordPress LearnPress<=4.2.6.8.2
Remediation
Information
Update to 4.2.6.9 or a higher version.
Event History
Aug 13, 2024
CVE Published
via MITRE·10:47 AM
Data Sourced
via MITRE·10:47 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39642?
CVE-2024-39642 has a medium severity rating due to its potential for exploitation by unauthorized users.
2
How do I fix CVE-2024-39642?
To address CVE-2024-39642, upgrade ThimPress LearnPress to version 4.2.6.8.3 or later.
3
What functionality is affected by CVE-2024-39642?
CVE-2024-39642 allows access to functionalities that are not properly constrained by Access Control Lists (ACLs).
4
Which versions of LearnPress are vulnerable to CVE-2024-39642?
LearnPress versions from n/a up to and including 4.2.6.8.2 are affected by CVE-2024-39642.
5
Who is impacted by CVE-2024-39642?
Users of ThimPress LearnPress versions prior to 4.2.6.8.3 are vulnerable to CVE-2024-39642.