Description
WordPress Plugin LMS by LifterLMS-Online Course, Membership & Learning Management System for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin's options. WordPress Plugin LMS by LifterLMS-Online Course, Membership & Learning Management System for WordPress version 3.34.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.35.0 or latest
References
https://blog.nintechnet.com/critical-vulnerability-fixed-in-wordpress-lifterlms-plugin/
https://plugins.svn.wordpress.org/lifterlms/trunk/readme.txt
Related Vulnerabilities
Contao Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-37626)
WordPress Plugin JS Job Manager Unspecified Vulnerability (1.0.9)
WordPress Plugin eCommerce Product Catalog for WordPress Cross-Site Request Forgery (2.9.43)