First published: Thu May 02 2024(Updated: )
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it possible for authenticated attackers, with subscriber level permissions and above, to read and modify content such as course questions, post titles, and taxonomies.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
MasterStudy LMS WordPress Plugin | <3.3.9 | |
MasterStudy LMS | <=3.3.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3942 is considered a medium severity vulnerability due to the potential unauthorized access and data modification it allows.
To fix CVE-2024-3942, update the MasterStudy LMS WordPress Plugin to version 3.3.9 or later.
The risks associated with CVE-2024-3942 include unauthorized access and modification of data, posing a threat to user privacy and data integrity.
Users of the MasterStudy LMS WordPress Plugin versions up to 3.3.8 are affected by CVE-2024-3942.
Yes, CVE-2024-3942 is exploitable remotely, requiring only authenticated access to impact the affected systems.