PT-2024-28487 · WordPress · Masterstudy Lms Wordpress Plugin

Lucio Sá

·

Published

2024-05-02

·

Updated

2025-01-21

·

CVE-2024-3942

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress versions up to, and including, 3.3.8
Description The issue allows authenticated attackers with subscriber level permissions and above to access, modify, and potentially cause loss of data due to a missing capability check on several functions. This enables them to read and modify content such as course questions, post titles, and taxonomies.
Recommendations For versions up to, and including, 3.3.8, update to a version that includes a fix for the missing capability check issue to prevent unauthorized access and modification of data.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-3942

Affected Products

Masterstudy Lms Wordpress Plugin