Unauthorized Access Risk in WP Courses LMS Due to Missing Capability Check
CVE-2024-12172
Key Information:
- Vendor
- Wordpress
- Status
- Vendor
- CVE Published:
- 12 December 2024
Summary
The WP Courses LMS plugin for WordPress is susceptible to unauthorized access due to a flaw in the wpc_update_user_meta_option() function, which lacks proper capability verification. This vulnerability impacts all versions up to and including 3.2.21. Authenticated attackers with at least Subscriber-level access can exploit this issue to alter arbitrary user metadata. Such manipulation can result in denial of access for administrators by setting wp_capabilities to 0, thereby jeopardizing the security and integrity of the affected WordPress installations.
Affected Version(s)
WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses * <= 3.2.21
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved