CVE-2023-35093: WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35093?
CVE-2023-35093 is a Broken Access Control vulnerability in the StylemixThemes MasterStudy LMS WordPress Plugin - for Online Courses and Education plugin <= 3.0.8 versions.
What is the severity of CVE-2023-35093?
The severity of CVE-2023-35093 is medium with a CVSS score of 6.5.
Who is affected by CVE-2023-35093?
The StylemixThemes MasterStudy LMS WordPress Plugin - for Online Courses and Education plugin <= 3.0.8 versions are affected by CVE-2023-35093.
How does CVE-2023-35093 work?
CVE-2023-35093 allows any logged-in users, such as subscribers, to view the "Orders" of the plugin and access order-related data like email, username, and more.
Is there a fix for CVE-2023-35093?
Yes, the vulnerability can be fixed by updating StylemixThemes MasterStudy LMS WordPress Plugin to a version higher than 3.0.8.