CVE-2024-43159: WordPress Masteriyo LMS plugin <= 1.11.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43159?
CVE-2024-43159 is classified as a Missing Authorization vulnerability that allows access to functionality not properly constrained by access control lists.
How do I fix CVE-2024-43159?
To fix CVE-2024-43159, upgrade Masteriyo - LMS or the WordPress Masteriyo LMS plugin to version 1.11.7 or later.
What versions are affected by CVE-2024-43159?
CVE-2024-43159 affects Masteriyo - LMS and WordPress Masteriyo LMS plugin versions up to and including 1.11.6.
What systems are impacted by CVE-2024-43159?
CVE-2024-43159 impacts systems running Masteriyo - LMS and the WordPress Masteriyo LMS plugin prior to version 1.11.7.
What are the risks associated with CVE-2024-43159?
The risks associated with CVE-2024-43159 include unauthorized access to sensitive functionalities and potential data exposure.