Record summary

CVE-2024-5483 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.8 due to incorrect implementation of get_items_permissions_check function. This makes it possible for unauthenticated attackers to extract basic information about website users, including their emails

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 5, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

Browse thimpress / LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

Default status: unaffected

CVE ListThrough 4.2.6.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLearnPress < 4.2.6.8.1 - Information DisclosureCVSS 5.3

LearnPress – WordPress LMS Plugin contains a sensitive information exposure caused by incorrect implementation of get_items_permissions_check function in all versions up to 4.2.6.8, letting unauthenticated attackers extract user emails and basic information.

Impact

Unauthenticated attackers can access sensitive user information, including emails, leading to privacy breaches.

Remediation

Update to version 4.2.6.9 or later.

WeaknessesCWE-200
Authorspussycat0x
Template tagscvecve2024wordpresswpscanwp-pluginlearnpressvulninfo-leak
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: http.html:"/wp-content/plugins/learnpress/"
FOFA: body="/wp-content/plugins/learnpress/"

Source: ProjectDiscovery

References

3