The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-07-02T11:01:35.868Z

Updated: 2024-08-01T21:33:04.602Z

Reserved: 2024-06-17T21:41:27.658Z

Link: CVE-2024-6099

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:04.602Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-02T11:15:10.650

Modified: 2024-07-02T18:08:53.233

Link: CVE-2024-6099

cve-icon Redhat

No data.