CVE-2024-1505
Last modified
CVE-2024-1505 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated attackers, with minimal permissions such as students, to elevate their user role to that of an administrator.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kodezen | Academy Lms | < 1.9.20 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-1505?
How severe is CVE-2024-1505?
How do I fix CVE-2024-1505?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-1499The Orbit Fox by ThemeIsle plugin for WordPress is vulnerabl…5.4
- CVE-2024-1500The Royal Elementor Addons and Templates plugin for WordPres…5.4
- CVE-2024-1501The Database Reset plugin for WordPress is vulnerable to Cro…4.7
- CVE-2024-1502The Tutor LMS – eLearning and online course solution plugin …4.3
- CVE-2024-1503The Tutor LMS – eLearning and online course solution plugin …4.3
- CVE-2024-1504The SecuPress Free — WordPress Security plugin for WordPress…4.3
- CVE-2024-1506The Prime Slider – Addons For Elementor plugin for WordPress…5.4
- CVE-2024-1507The Prime Slider – Addons For Elementor plugin for WordPress…5.4
- CVE-2024-1508The Prime Slider – Addons For Elementor plugin for WordPress…5.4
- CVE-2024-1509Brocade ASCG before 3.2.0 Web Interface is not enforcing H…9.1
- CVE-2024-1510The WP Shortcodes Plugin — Shortcodes Ultimate plugin for Wo…5.4
- CVE-2024-1511The parisneo/lollms-webui repository is susceptible to a pat…9.8
Are you affected by CVE-2024-1505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
