QID 730433

Date Published: 2022-04-14

QID 730433: WordPress Plugin MasterStudy LMS Privilege Escalation Vulnerability

WordPress LMS Plugin MasterStudy is the comprehensive software for feature-rich educational websites. The LMS plugin can turn any WordPress website into a professional online platform that enjoys all industry-specific e-learning and LMS features.

CVE-2022-0441: The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin.

Affected Versions:
MasterStudy LMS WordPress plugin versions prior to 2.7.6

QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the MasterStudy LMS plugin.

Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to register as an admin on the affected targets.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are requested to update to MasterStudy LMS 2.7.6 or later to mitigate this vulnerability.

    Vendor References

    CVEs related to QID 730433

    Software Advisories
    Advisory ID Software Component Link
    MasterStudy LMS Release Notes URL Logo wordpress.org/plugins/masterstudy-lms-learning-management-system/advanced/