CVE-2024-3942: MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it possible for authenticated attackers, with subscriber level permissions and above, to read and modify content such as course questions, post titles, and taxonomies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3942?
CVE-2024-3942 is considered a medium severity vulnerability due to the potential unauthorized access and data modification it allows.
How do I fix CVE-2024-3942?
To fix CVE-2024-3942, update the MasterStudy LMS WordPress Plugin to version 3.3.9 or later.
What are the risks associated with CVE-2024-3942?
The risks associated with CVE-2024-3942 include unauthorized access and modification of data, posing a threat to user privacy and data integrity.
Who is affected by CVE-2024-3942?
Users of the MasterStudy LMS WordPress Plugin versions up to 3.3.8 are affected by CVE-2024-3942.
Is CVE-2024-3942 exploitable remotely?
Yes, CVE-2024-3942 is exploitable remotely, requiring only authenticated access to impact the affected systems.