CVE-2024-43158: WordPress Masteriyo LMS plugin <= 1.11.4 - Broken Access Control vulnerability
Published Nov 1, 2024
·Updated
Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4.
Affected Software
3 affected components
masteriyo Masteriyo - LMS<=1.11.4
WordPress Masteriyo LMS plugin<=1.11.4
masteriyo Masteriyo WordPress<1.11.5
Remediation
Information
Update to 1.11.5 or a higher version.
Event History
Nov 1, 2024
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-43158?
CVE-2024-43158 has a high severity rating due to the missing authorization vulnerabilities allowing unauthorized access to restricted functionalities.
2
How do I fix CVE-2024-43158?
To fix CVE-2024-43158, update Masteriyo - LMS to the latest version that addresses the broken access control issues.
3
What versions are affected by CVE-2024-43158?
CVE-2024-43158 affects Masteriyo - LMS versions up to and including 1.11.4.
4
What type of vulnerability is CVE-2024-43158?
CVE-2024-43158 is classified as a Missing Authorization vulnerability leading to broken access control.
5
Who is impacted by CVE-2024-43158?
Users of Masteriyo - LMS versions up to 1.11.4 are impacted by CVE-2024-43158 due to inadequate access control.