The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated attackers, with minimal permissions such as students, to elevate their user role to that of an administrator.
References
Configurations
History
22 Jan 2025, 20:57
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:kodezen:academy_lms:*:*:*:*:*:wordpress:*:* | |
References | () https://plugins.trac.wordpress.org/changeset/3037880/academy#file473 - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/b150f90a-ccb7-4c19-a4b3-eaf9ec264ba8?source=cve - Third Party Advisory | |
CWE | NVD-CWE-noinfo | |
First Time |
Kodezen
Kodezen academy Lms |
Information
Published : 2024-03-13 16:15
Updated : 2025-01-22 20:57
NVD link : CVE-2024-1505
Mitre link : CVE-2024-1505
CVE.ORG link : CVE-2024-1505
JSON object : View
Products Affected
kodezen
- academy_lms
CWE