QID 730433
Date Published: 2022-04-14
QID 730433: WordPress Plugin MasterStudy LMS Privilege Escalation Vulnerability
WordPress LMS Plugin MasterStudy is the comprehensive software for feature-rich educational websites. The LMS plugin can turn any WordPress website into a professional online platform that enjoys all industry-specific e-learning and LMS features.
CVE-2022-0441: The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin.
Affected Versions:
MasterStudy LMS WordPress plugin versions prior to 2.7.6
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the MasterStudy LMS plugin.
Successful exploitation of this vulnerability may allow an unauthenticated remote attacker to register as an admin on the affected targets.
- MasterStudy LMS Release Notes -
wordpress.org/plugins/masterstudy-lms-learning-management-system/advanced/
CVEs related to QID 730433
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| MasterStudy LMS Release Notes |
|