First published: Mon Jul 22 2024(Updated: )
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
MasterStudy LMS WordPress Plugin | <3.3.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5973 is classified as a high severity vulnerability due to its potential to allow unauthorized access to instructor functionalities.
To fix CVE-2024-5973, update the MasterStudy LMS WordPress Plugin to version 3.3.24 or later.
CVE-2024-5973 affects the MasterStudy LMS WordPress Plugin versions prior to 3.3.24.
An attacker could create unauthorized instructor accounts, gaining access to restricted functionalities of the plugin.
Using the MasterStudy LMS WordPress Plugin is safe as long as it is updated to version 3.3.24 or later to mitigate CVE-2024-5973.