
According to researchers, vulnerabilities have been identified in WordPress plugins commonly used by e-learning platforms. The vulnerabilities involve significant security issues.
Check Point published a study on three popular WordPress plugins, LearnPress, LearnDash and LifterLMS, systems that are widely used for educational purposes, especially in this period when distance learning has become an everyday occurrence for many users.
LMS (learning management systems) platforms can be used to manage online courses (both free and paid), facilitate discussion between students, etc.
LearnPress , developed by ThimPress , is a plugin for creating and publishing courses with over 80,000 active installations. LearnDash is another LMS plugin used by universities and companies Fortune 500 (there are about 33,000 sites with this plugin). Finally, LifterLMS is a plugin with over 10,000 installations.

Check Point examined WordPress plugins and found that there are four vulnerabilities: CVE-2020-6008, CVE-2020-6009, CVE-2020-6010, and CVE-2020-6011, which could allow an attacker to gain elevated privileges and execute code remotely (RCE).
"These vulnerabilities allow both legitimate students and unauthorized users to obtain sensitive information or take control of LMS platforms," the team said.
According to Check Point, students or even remote, unauthorized attackers could exploit the security and proceed to hijack e-learning platforms, steal sensitive data, change grades, forge certificates, and possibly steal money from LMS platforms that offer paid courses.
The analysis of WordPress plugins was conducted in March. The first vulnerability, CVE-2020-6010, affects LearnPress versions 3.2.6.7 and later. It is a SQL injection vulnerability.
The second vulnerability, CVE-2020-6011, also affects LearnPress. This bug could be exploited to give a user the same privileges as a teacher.
"Both vulnerabilities we reported received the same treatment from the developer—the vulnerable functions were fixed with the new update," the researchers noted.
The same plugin was also found with another bug, CVE-2020-11511, discovered by the Wordfence on April 28. Version 3.2.6.9 and later are affected by the bug, which can be exploited to allow someone to gain more privileges.
LearnDash (version 3.1.6 and later) is vulnerable to the CVE-2020-6009 vulnerability, which could allow an SQL injection attack by an unauthorized user.
The vulnerability CVE-2020-6008 affects LifterLMS (version 3.37.15 and later). This bug could allow attackers to execute code remotely.
Following the publication of the report, updates were made to WordPress plugins to address the security issues. Users should make sure their plugins are up to date to stay protected.
“Top educational institutions, as well as many online academies, rely on the systems we investigated to deliver their online courses and training programs,” commented Check Point researcher Omri Herscovici.
“We urge relevant educational institutions to upgrade all platforms to the latest versions.”
