MasterStudy LMS WordPress Plugin – for Online Courses and Education, c1205f27515b7932bb2cf9e3082131a62daafdfe
- CVE, Research URL
- Home page URL
-
Security reports for MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Published on
- Apr 03, 2023
- Research Description
- MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 2.9.35 MasterStudy LMS WordPress Plugin <= 2.9.34 - Missing Authorization via wp_ajax_stm_wpcfto_get_settings The MasterStudy LMS WordPress Plugin is vulnerable to unauthorized access of data due to a missing capability check on an anonymous function called by the stm_wpcfto_get_settings AJAX action in versions up to, and including, 2.9.345. This makes it possible for authenticated attackers with subscriber-level permissions or above to access settings data.
- Affected versions
-
max 2.9.35.
- Status
-
vulnerable