CVE-2024-6099: LearnPress – WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'checkvalidatefields' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LearnPress – WordPress LMS Pluginto a version that resolves this vulnerability.Fixed in 4.2.6.8.1 - Configuration
Ensure WordPress user registration remains disabled to prevent unauthenticated bypass to user registration.
WordPress registration = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6099?
CVE-2024-6099 is classified as a medium severity vulnerability due to its potential impact on user registration processes.
How do I fix CVE-2024-6099?
To fix CVE-2024-6099, upgrade the LearnPress plugin to version 4.2.6.8.2 or higher.
Who is affected by CVE-2024-6099?
Users of the LearnPress – WordPress LMS Plugin in versions up to and including 4.2.6.8.1 are affected by CVE-2024-6099.
What can attackers do with CVE-2024-6099?
Attackers can exploit CVE-2024-6099 to bypass user registration checks, potentially allowing unauthorized user registrations.
Is authentication required to exploit CVE-2024-6099?
No, CVE-2024-6099 can be exploited by unauthenticated users, making it particularly concerning.