Skip to main content

Unprotected Alternate Channel

CVE-2024-6099

Severity Medium
Score 5.3/10

Summary

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This is due to missing checks in the 'check_validate_fields' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-420 - Unprotected Alternate Channel

The software protects a primary channel, but it does not use the same level of protection for an alternate channel.

References

Advisory Timeline

  • Published