WordPress Plugin Vulnerabilities

MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import

Description

The plugin does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
vuxvinh
Submitter
vuxvinh
Verified
Yes

Timeline

Publicly Published
2026-09-22 (about 2 days ago)
Added
2026-09-22 (about 1 day ago)
Last Updated
2026-09-22 (about 1 day ago)

Other