
Cloud Vulnerability DB
A community-led vulnerabilities database
The LearnPress WordPress plugin before version 3.2.6.9 contained a privilege escalation vulnerability (CVE-2020-11511) that allowed remote attackers to escalate the privileges of any user to LP Instructor. The vulnerability was discovered in April 2020 and affected all versions of the plugin up to 3.2.6.8 (Wordfence, WPScan).
The vulnerability existed due to improper authorization checks in the plugin's functionality. Specifically, the 'accept-to-be-teacher' action parameter lacked proper capability checks and nonce verification. The 'LP Instructor' role grants the 'unfiltered_html' capability, which allows users to insert posts containing malicious JavaScript. The vulnerability received a CVSS score of 8.6 (High) (WPScan).
The vulnerability allowed attackers to elevate the privileges of any user to LP Instructor by sending a request to wp-admin/admin-post.php with the action parameter set to accept-to-be-teacher and specifying an arbitrary user_id parameter. Since the LP Instructor role grants the unfiltered_html capability, compromised accounts could be used to insert malicious JavaScript into posts (WPScan).
The vulnerability could be exploited by sending a request to any location within wp-admin with the action parameter set to accept-to-be-teacher. This was possible because the learn_press_accept_become_a_teacher function runs on the plugins_loaded action without proper security checks (WPScan).
The vulnerability was patched in LearnPress version 3.2.6.9. Users are advised to update to this version or later to mitigate the risk (Wordfence).
The vulnerability was one of several critical bugs found in popular e-learning plugins for WordPress sites during early 2020, highlighting the increased importance of securing online learning platforms during the shift to remote education (Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."