May 4, 2020 By David Bisson < 1 min read

Security researchers discovered that students could abuse vulnerabilities in certain learning management system (LMS) plugins to access records and edit data.

Check Point Research conducted a security audit of three popular WordPress LMS plugins: LearnPress, LearnDash and LifterLMS. Those plugins were installed on 100,000 educational platforms at the time of analysis, including both traditional universities and hundreds of online academies.

The researchers uncovered several vulnerabilities that were worthy of attention. For instance, they observed one security flaw through which registered users could have elevated their privileges to those belonging to a teacher. They could have then used those rights to retrieve test answers, change the test answers of their fellow students or even change their own grades.

Through some of the other bugs, students and unauthenticated users could have even stolen sensitive information such as usernames, passwords and full names.

Vulnerabilities in Other LMS Plugins and Software

The three WordPress LMS plugins discussed above aren’t the only educational software programs that have suffered from security vulnerabilities. As reported by InfoWorld back in 2017, researchers observed that they could have exploited several vulnerabilities in Moodle to create secret administrative accounts and execute malicious PHP code. And in December 2019, Cisco Talos uncovered three SQL injection vulnerabilities in the Forma LMS.

Strengthen Your Organization’s Patching Capabilities

Security professionals can help their organizations remediate vulnerabilities such as the ones discussed above by breaking down the silos that separate departments. By improving interdepartmental cooperation, organizations can more easily remedy critical vulnerabilities on a timely basis. Organizations also need to maintain and continually manage an inventory of assets that is prioritized based on their value to the business.

More from

Protecting your digital assets from non-human identity attacks

4 min read - Untethered data accessibility and workflow automation are now foundational elements of most digital infrastructures. With the right applications and protocols in place, businesses no longer need to feel restricted by their lack of manpower or technical capabilities — machines are now filling those gaps.The use of non-human identities (NHIs) to power business-critical applications — especially those used in cloud computing environments or when facilitating service-to-service connections — has opened the doors for seamless operational efficiency. Unfortunately, these doors aren’t the…

Communication platforms play a major role in data breach risks

4 min read - Every online activity or task brings at least some level of cybersecurity risk, but some have more risk than others. Kiteworks Sensitive Content Communications Report found that this is especially true when it comes to using communication tools.When it comes to cybersecurity, communicating means more than just talking to another person; it includes any activity where you are transferring data from one point online to another. Companies use a wide range of different types of tools to communicate, including email,…

Research finds 56% increase in active ransomware groups

4 min read - Any good news is welcomed when evaluating cyber crime trends year-over-year. Over the last two years, IBM’s Threat Index Reports have provided some minor reprieve in this area by showing a gradual decline in the prevalence of ransomware attacks — now accounting for only 17% of all cybersecurity incidents compared to 21% in 2021. Unfortunately, it’s too early to know if this trendline will continue. A recent report released by Searchlight Cyber shows that there has been a 56% increase in…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today