WordPress Plugin Vulnerabilities

MasterStudy LMS < 3.3.24 - Privilege Escalation to Instructor

Description

The plugin does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

Proof of Concept

Affects Plugins

References

YouTube Video

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Jaime F. Murillo
Submitter
Jaime F. Murillo
Verified
Yes

Timeline

Publicly Published
2024-07-01 (about 1 year ago)
Added
2024-07-01 (about 1 year ago)
Last Updated
2025-08-26 (about 3 months ago)

Other