CVE-2024-5483: LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of getitemspermissionscheck function. This makes it possible for unauthenticated attackers to extract basic information about website users, including their emails
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5483?
CVE-2024-5483 is classified as a high-severity vulnerability due to the risk of sensitive information exposure.
How do I fix CVE-2024-5483?
To fix CVE-2024-5483, update the LearnPress – WordPress LMS Plugin to version 4.2.6.8.1 or later.
Who is affected by CVE-2024-5483?
CVE-2024-5483 affects all versions of the LearnPress – WordPress LMS Plugin up to and including 4.2.6.8.
What type of vulnerability is CVE-2024-5483?
CVE-2024-5483 is a vulnerability for sensitive information exposure due to improper permissions checks.
Can unauthenticated attackers exploit CVE-2024-5483?
Yes, unauthenticated attackers can exploit CVE-2024-5483 to access sensitive information.