plugin

Pmpro Courses Vulnerabilities

10 known security issues reported for the Pmpro Courses WordPress plugin. Most recent disclosed Jun 19, 2024.

1 critical 3 medium

Running Pmpro Courses on your site? Check whether your installed version is affected.

Scan your site free

Premium Courses &amp; eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS &amp; TutorLMS [pmpro-courses] < 1.2.4 (closed)

unknown

[en] Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Jun 19, 2024

CVE-2023-39990 on NVD →

Premium Courses &amp; eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS &amp; TutorLMS [pmpro-courses] < 1.2.5 (closed)

unknown

Update the WordPress Paid Memberships Pro - Courses for Membership Add On plugin to the latest available version (at least 1.2.5). WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Paid Memberships Pro Plugin. This could allow a malicious actor to inject malicious scripts, suc...

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Aug 9, 2023

Paid Memberships Pro - Courses for Membership Add On <= 1.2.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmpro_courses_modules' setting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

CVSS:
4.4
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Aug 8, 2023

Paid Memberships Pro - Courses for Membership Add On <= 1.2.3 - Cross-Site Request Forgery to Course Modifications

medium

The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce verification on the pmpro_courses_update_course_callback() and pmpro_courses_remove_course_callback() functions called via AJAX actions in versions up to, and including, 1.2.3....

CVSS:
4.3
Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Aug 8, 2023

Paid Memberships Pro - Courses for Membership Add On <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Course Modifications

medium

The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the pmpro_courses_update_course_callback() and pmpro_courses_remove_course_callback() functions called via AJAX actions in versions up to, and including, 1...

CVSS:
4.3
Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Aug 8, 2023

CVE-2023-39990 on NVD →

Premium Courses &amp; eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS &amp; TutorLMS [pmpro-courses] < 1.2.4 (closed)

unknown

The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the pmpro_courses_update_course_callback() and pmpro_courses_remove_course_callback() functions called via AJAX actions in versions up to, and including, 1...

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Aug 8, 2023

Premium Courses &amp; eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS &amp; TutorLMS [pmpro-courses] < 1.2.5 (closed)

unknown

The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmpro_courses_modules' setting in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with...

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Aug 8, 2023

Premium Courses &amp; eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS &amp; TutorLMS [pmpro-courses] < 1.2.4 (closed)

unknown

The Paid Memberships Pro - Courses for Membership Add On plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce verification on the pmpro_courses_update_course_callback() and pmpro_courses_remove_course_callback() functions called via AJAX actions in versions up to, and including, 1.2.3....

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Aug 8, 2023

Premium Courses & eLearning <= 1.0.5 - SQL Injection

critical

The Premium Courses & eLearning plugin for WordPress is vulnerable to SQL Injection via the ‘level_ids’ parameter in several of its modules in versions up to, and including, 1.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it poss...

CVSS:
9.8
Affected:
up to 1.0.5
Fixed in:
1.1
Disclosed:
Jun 15, 2022

Premium Courses &amp; eLearning with Paid Memberships Pro for LearnDash, LifterLMS, Sensei LMS &amp; TutorLMS [pmpro-courses] < 1.1 (closed)

unknown

The Premium Courses & eLearning plugin for WordPress is vulnerable to SQL Injection via the ‘level_ids’ parameter in several of its modules in versions up to, and including, 1.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it poss...

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jun 15, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database