Record summary

CVE-2020-26876 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as exploited in the wild in September 2020. This occurs because show_in_rest is enabled for custom post types (e.g., /wp-json/wp/v2/course and /wp-json/wp/v2/lesson exist).

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 7, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWordPress WP Courses Plugin Information DisclosureCVSS 7.5

WordPress WP Courses Plugin < 2.0.29 contains a critical information disclosure which exposes private course videos and materials.

Impact

An attacker can exploit this vulnerability to gain sensitive information about the WordPress WP Courses Plugin.

Remediation

Update to the latest version of the WordPress WP Courses Plugin (1.0.9) to fix the information disclosure vulnerability.

WeaknessesCWE-306
Authorsdwisiswant0
Template tagscvecve2020wordpresswp-pluginexposureedbwpcoursespluginvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:wpcoursesplugin:wp-courses:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4