WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control
CVE-2023-35093
6.5MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 22 June 2023
Summary
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
Affected Version(s)
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.0.8
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafshanzani Suhada (Patchstack Alliance)