CVE-2024-4444: LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'createaccount' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LearnPress – WordPress LMS Pluginto a version that resolves this vulnerability.Fixed in 4.2.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4444?
CVE-2024-4444 is considered a critical vulnerability due to the potential for unauthenticated attackers to bypass user registration.
How do I fix CVE-2024-4444?
To fix CVE-2024-4444, update the LearnPress – WordPress LMS Plugin to version 4.2.6.6 or later.
Who is affected by CVE-2024-4444?
CVE-2024-4444 affects all installations of the LearnPress – WordPress LMS Plugin versions up to and including 4.2.6.5.
What type of attack does CVE-2024-4444 enable?
CVE-2024-4444 enables attackers to create user accounts without authentication due to inadequate checks.
When was CVE-2024-4444 discovered?
CVE-2024-4444 was disclosed in the context of security vulnerabilities affecting the LearnPress plugin prior to its version update.