CVE-2024-2409: MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the registeruser() function called by the 'wpajaxnoprivstmlmsregister' AJAX action. This makes it possible for unauthenticated attackers to register a user with administrator-level privileges when MasterStudy LMS Pro is installed and the LMS Forms Editor add-on is enabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2409?
CVE-2024-2409 has a severity that suggests it could lead to privilege escalation if exploited.
How do I fix CVE-2024-2409?
To fix CVE-2024-2409, update the MasterStudy LMS plugin for WordPress to version 3.3.2 or later.
Who is affected by CVE-2024-2409?
All users of the MasterStudy LMS plugin for WordPress versions up to and including 3.3.1 are affected by CVE-2024-2409.
What kind of attack does CVE-2024-2409 enable?
CVE-2024-2409 enables a privilege escalation attack that could allow unauthenticated users to register as privileged users.
When was CVE-2024-2409 disclosed?
CVE-2024-2409 was disclosed recently and affects all versions of the MasterStudy LMS plugin prior to the 3.3.2 patch.