First published: Mon Sep 11 2023(Updated: )
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.
Credit: Revan Arifio contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
StylemixThemes MasterStudy LMS WordPress | <3.0.18 | |
<3.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4278 is a vulnerability in the MasterStudy LMS WordPress Plugin before version 3.0.18.
CVE-2023-4278 has a severity rating of 7.5 (high).
CVE-2023-4278 allows anyone to register on the site as an instructor in the MasterStudy LMS plugin before version 3.0.18, enabling them to add courses and/or posts.
To fix CVE-2023-4278, you should update the MasterStudy LMS WordPress plugin to version 3.0.18 or higher.
Yes, you can find more details about the vulnerability on the WPScan website at https://wpscan.com/vulnerability/cb3173ec-9891-4bd8-9d05-24fe805b5235.