The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function in all versions up to, and including, 4.2.6.8.1. This makes it possible for unauthenticated attackers to bypass disabled user registration to create a new account with the default role.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-07-02T11:01:35.401Z
Updated: 2024-08-01T21:33:03.291Z
Reserved: 2024-06-17T18:01:31.636Z
Link: CVE-2024-6088
Vulnrichment
Updated: 2024-08-01T21:33:03.291Z
NVD
Status : Modified
Published: 2024-07-02T11:15:10.463
Modified: 2024-11-21T09:48:56.297
Link: CVE-2024-6088
Redhat
No data.