ThimPress LearnPress Export Import
cpe:2.3:a:thimpress:learnpress_export_import:*:*:*:*:wordpress:*:*
- <= 4.1.0
A vulnerability exists in the LearnPress Export Import WordPress extension, specifically in versions through 4.1.0. The issue arises from a lack of proper capability checks in the 'delete_migrated_data' function, allowing unauthenticated attackers to delete courses that were migrated from Tutor LMS. To exploit this vulnerability, the Tutor LMS plugin must be installed and activated.
Exploitation of this vulnerability allows for unauthorized deletion of Tutor LMS courses that have been migrated to LearnPress.
The vulnerability can be reproduced by sending a DELETE request to the '/delete-migrated-data/tutor' endpoint of the WordPress REST API. This request can be made without authentication, which triggers the deletion of migrated Tutor LMS courses on the site.
Users are advised to update the LearnPress Export Import plugin to version 4.1.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.