CVE-2024-3136: MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3136?
CVE-2024-3136 is considered a high severity vulnerability due to its potential for unauthorized file execution.
How do I fix CVE-2024-3136?
To fix CVE-2024-3136, update the MasterStudy LMS plugin for WordPress to version 3.3.4 or later.
What type of vulnerability is CVE-2024-3136?
CVE-2024-3136 is classified as a Local File Inclusion (LFI) vulnerability.
Who is affected by CVE-2024-3136?
All versions of the MasterStudy LMS plugin for WordPress up to and including version 3.3.3 are affected by CVE-2024-3136.
Can CVE-2024-3136 be exploited by authenticated users?
No, CVE-2024-3136 can be exploited by unauthenticated attackers.