CVE-2024-24882: WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
Published May 17, 2024
·Updated
Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.
Affected Software
3 affected components
masteriyo Masteriyo LMS>n/a, <=1.7.2
Masteriyo WordPress LMS<=1.7.2
themegrill Masteriyo Wordpress<1.7.3
Remediation
Information
Update to 1.7.3 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·08:48 AM
Data Sourced
via MITRE·08:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24882?
CVE-2024-24882 is classified as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-24882?
To fix CVE-2024-24882, update your Masteriyo LMS to version 1.7.3 or later.
3
Which versions of Masteriyo LMS are affected by CVE-2024-24882?
CVE-2024-24882 affects all versions of Masteriyo LMS from n/a through 1.7.2.
4
What type of vulnerability is CVE-2024-24882?
CVE-2024-24882 is an Improper Privilege Management vulnerability that allows privilege escalation.
5
Can CVE-2024-24882 affect my WordPress LMS using Masteriyo?
Yes, CVE-2024-24882 can affect your WordPress LMS by Masteriyo if it is version 1.7.2 or lower.