CVE-2024-5483
LearnPress – WordPress LMS Plugin <= 4.2.6.8 - Basic Information Disclosure via JSON API
Record summary
CVE-2024-5483 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to extract basic information about website users, including their emails
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 5, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesBrowse thimpress / LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesDefault status: unaffected | CVE List | Through 4.2.6.8 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLearnPress < 4.2.6.8.1 - Information DisclosureCVSS 5.3
LearnPress – WordPress LMS Plugin contains a sensitive information exposure caused by incorrect implementation of get_items_permissions_check function in all versions up to 4.2.6.8, letting unauthenticated attackers extract user emails and basic information.
Impact
Unauthenticated attackers can access sensitive user information, including emails, leading to privacy breaches.
Remediation
Update to version 4.2.6.9 or later.
Source: ProjectDiscovery