WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control
CVE-2023-35093

6.5MEDIUM

Key Information:

Summary

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.

Affected Version(s)

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.0.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafshanzani Suhada (Patchstack Alliance)
.