CVE-2023-4278: MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.
Credit
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4278?
CVE-2023-4278 is a vulnerability in the MasterStudy LMS WordPress Plugin before version 3.0.18.
What is the severity of CVE-2023-4278?
CVE-2023-4278 has a severity rating of 7.5 (high).
How does CVE-2023-4278 affect the MasterStudy LMS plugin?
CVE-2023-4278 allows anyone to register on the site as an instructor in the MasterStudy LMS plugin before version 3.0.18, enabling them to add courses and/or posts.
How can I fix CVE-2023-4278 in the MasterStudy LMS plugin?
To fix CVE-2023-4278, you should update the MasterStudy LMS WordPress plugin to version 3.0.18 or higher.
Is there any additional information about CVE-2023-4278?
Yes, you can find more details about the vulnerability on the WPScan website at https://wpscan.com/vulnerability/cb3173ec-9891-4bd8-9d05-24fe805b5235.