WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control
CVE-2023-35093
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 June 2023
What is CVE-2023-35093?
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
Affected Version(s)
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.0.8