First published: Tue Jul 02 2024(Updated: )
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
ThimPress LearnPress | <4.2.6.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6099 is classified as a medium severity vulnerability due to its potential impact on user registration processes.
To fix CVE-2024-6099, upgrade the LearnPress plugin to version 4.2.6.8.2 or higher.
Users of the LearnPress – WordPress LMS Plugin in versions up to and including 4.2.6.8.1 are affected by CVE-2024-6099.
Attackers can exploit CVE-2024-6099 to bypass user registration checks, potentially allowing unauthorized user registrations.
No, CVE-2024-6099 can be exploited by unauthenticated users, making it particularly concerning.