The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated attackers, with minimal permissions such as students, to elevate their user role to that of an administrator.
References
Configurations
History
22 Jan 2025, 20:57
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:kodezen:academy_lms:*:*:*:*:*:wordpress:*:* | |
First Time |
Kodezen academy Lms
Kodezen |
|
CWE | NVD-CWE-noinfo | |
References | () https://plugins.trac.wordpress.org/changeset/3037880/academy#file473 - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/b150f90a-ccb7-4c19-a4b3-eaf9ec264ba8?source=cve - Third Party Advisory |
21 Nov 2024, 08:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset/3037880/academy#file473 - | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/b150f90a-ccb7-4c19-a4b3-eaf9ec264ba8?source=cve - |
13 Mar 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-13 16:15
Updated : 2025-01-22 20:57
NVD link : CVE-2024-1505
Mitre link : CVE-2024-1505
CVE.ORG link : CVE-2024-1505
JSON object : View
Products Affected
kodezen
- academy_lms
CWE