MasterStudy LMS WordPress Plugin – for Online Courses and Education, CVE-2023-35093
- CVE, Research URL
- Home page URL
-
Security reports for MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Published on
- Jun 22, 2023
- Research Description
- Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
- Affected versions
-
Min -, max 3.0.9.
- Status
-
vulnerable