CVE-2024-1904: MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the searchposts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose draft post titles and excerpts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1904?
CVE-2024-1904 is considered a moderate severity vulnerability that allows unauthorized access to data in the MasterStudy LMS plugin.
How do I fix CVE-2024-1904?
To fix CVE-2024-1904, update the MasterStudy LMS plugin to version 3.3.0 or later.
Who is affected by CVE-2024-1904?
CVE-2024-1904 affects installations of the MasterStudy LMS plugin for WordPress versions up to and including 3.2.13.
What types of attacks can CVE-2024-1904 enable?
CVE-2024-1904 can enable authenticated attackers with subscriber-level access to expose sensitive data.
What versions of MasterStudy LMS are vulnerable to CVE-2024-1904?
Versions of MasterStudy LMS up to and including 3.2.13 are vulnerable to CVE-2024-1904.