CVE-2023-3345: LMS by Masteriyo < 1.6.8 - Information Exposure
The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Other sources
The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3345?
CVE-2023-3345 has been classified as a medium severity vulnerability.
How do I fix CVE-2023-3345?
To fix CVE-2023-3345, update the LMS by Masteriyo WordPress plugin to version 1.6.8 or later.
What type of vulnerability is CVE-2023-3345?
CVE-2023-3345 is an authorization vulnerability affecting specific REST API endpoints.
Who is affected by CVE-2023-3345?
Students using the LMS by Masteriyo WordPress plugin prior to version 1.6.8 are affected by CVE-2023-3345.
What data can be exposed due to CVE-2023-3345?
CVE-2023-3345 allows unauthorized students to retrieve the email addresses of other students.