5 results (0.037 seconds)

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 1

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have. El complemento de WordPress MasterStudy LMS WordPress Plugin anterior a 3.3.24 no impide que los estudiantes creen cuentas de instructor, que podrían usarse para obtener acceso a funcionalidades que no deberían tener. The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.23. This is due to insufficient role restrictions when registering through the stm_lms_register AJAX endpoint. This makes it possible for unauthenticated attackers to register on sites with Instructor level access. • https://wpscan.com/vulnerability/59abfb7c-d5ea-45f2-ab9a-4391978e3805 • CWE-269: Improper Privilege Management •

CVSS: 7.5EPSS: 3%CPEs: 1EXPL: 3

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts. El complemento de WordPress MasterStudy LMS WordPress anterior a 3.0.18 no cuenta con controles adecuados durante el registro, lo que permite que cualquiera se registre en el sitio como instructor. Luego pueden agregar cursos y/o publicaciones. The MasterStudy LMS plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.0.17. • https://www.exploit-db.com/exploits/51735 https://github.com/revan-ar/CVE-2023-4278 http://packetstormsecurity.com/files/175007/WordPress-Masterstudy-LMS-3.0.17-Account-Creation.html https://wpscan.com/vulnerability/cb3173ec-9891-4bd8-9d05-24fe805b5235 • CWE-269: Improper Privilege Management •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more. The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_lms_create_term function in versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary course categories. • https://patchstack.com/database/vulnerability/masterstudy-lms-learning-management-system/wordpress-masterstudy-lms-plugin-3-0-7-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.7 versions. The MasterStudy LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/masterstudy-lms-learning-management-system/wordpress-masterstudy-lms-plugin-3-0-7-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 29%CPEs: 1EXPL: 5

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin El plugin MasterStudy LMS de WordPress versiones anteriores a 2.7.6, no comprueba algunos parámetros dados cuando es registrada una nueva cuenta, permitiendo a usuarios no autenticados registrarse como administradores MasterStudy LMS, a WordPress plugin, prior to 2.7.6 is affected by a privilege escalation where an unauthenticated user is able to create an administrator account for wordpress itself. • https://www.exploit-db.com/exploits/50752 https://github.com/biulove0x/CVE-2022-0441 https://github.com/tegal1337/CVE-2022-0441 https://github.com/kyukazamiqq/CVE-2022-0441 https://plugins.trac.wordpress.org/changeset/2667195 https://wpscan.com/vulnerability/173c2efe-ee9c-4539-852f-c242b4f728ed https://gist.github.com/numanturle/4762b497d3b56f1a399ea69aa02522a6 • CWE-269: Improper Privilege Management •