Advertisement






WordPress WP Courses 2.0.29 Information Disclosure / Authorization Bypass

CVE Category Price Severity
CVE-2020-13933 CWE-285 $500 High
Author Risk Exploitation Type Date
Mehran Moin High Remote 2020-09-28
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020090130

Below is a copy:

WordPress WP Courses 2.0.29 Information Disclosure / Authorization Bypass
WP Courses is a Wordpress plugin allowing to define courses with 
lessons. The course can be:

- accessible to everyone without authentication;
- only available for logged-in users;
- only available for logged-in and paying users.

In the latter case, only when a user is registered to WordPress and has 
bought the product via a third plugin (for example WooCommerce) the 
contents of the lessons are shown.

We have stumbled upon a severe information disclosure vulnerability on 
WP Course <= 2.0.29 that gives an unauthenticated attacker the ability 
to exfiltrate all the content of courses (for example videos links, 
etc...) through the Wordpress REST API (/wp-json).

We have published more details and a root cause analysis in the 
following link: 
https://www.redtimmy.com/critical-information-disclosure-on-wp-courses-plugin-exposes-private-course-videos-and-materials/

A CVE has been requested but not assigned yet.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum