Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-35093: WordPress MasterStudy LMS plugin <= 3.0.8 - Broken Access Control vulnerability - Patchstack

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the “Orders” of the plugin and get the data related to the order like email, username, and more.

CVE
#vulnerability#wordpress

6.5

Medium severity CVSS 3.1 score

Solution

No fix

No patched version is available. Refused by the vendor.

Found this useful? Thank Rafshanzani Suhada for reporting this vulnerability. Buy a coffee ☕

Rafshanzani Suhada discovered and reported this Broken Access Control vulnerability in WordPress MasterStudy LMS Plugin. This vulnerability has not been known to be fixed yet.

Other vulnerabilities in this plugin

2 present

4 patched

View all

Report to Patchstack Alliance bounty platform and earn monthly cash prizes.

Learn more

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907