Description
The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as exploited in the wild in September 2020. This occurs because show_in_rest is enabled for custom post types (e.g., /wp-json/wp/v2/course and /wp-json/wp/v2/lesson exist).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:03:22.690Z
Reserved: 2020-10-07T00:00:00.000Z
Link: CVE-2020-26876
No data.
Status : Modified
Published: 2020-10-07T17:15:15.863
Modified: 2024-11-21T05:20:23.587
Link: CVE-2020-26876
No data.
OpenCVE Enrichment
No data.
Weaknesses