CVE-2020-11511: The LearnPress plugin before 3.2.6.9 for WordPress allows remote attackers to escalate the privileges of any user to LP
highvulnerability
security
Summary
CVE-2020-11511 is a privilege escalation vulnerability (where an attacker can gain higher access levels than they should have) in the LearnPress plugin for WordPress before version 3.2.6.9. Attackers can exploit the 'accept-to-be-teacher' action parameter to upgrade any user's account to LP Instructor status without proper authorization.
Vulnerability Details
CVSS Score
8.1(high)
EPSS (30-day exploit probability)
EPSS: 2.8%
Classification
Attack SophisticationTrivial
Original source: https://nvd.nist.gov/vuln/detail/CVE-2020-11511
First tracked: February 15, 2026 at 08:37 PM
Classified by LLM (prompt v3) · confidence: 95%