CVE-2023-4278
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.
- Affected products
- Masterstudy Lms Wordpress Plugin
- Stylemixthemes Masterstudy Lms
- < 3.0.18
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 3.5% (88th percentile)
- NVD status
- Modified
- Published
- 2023-09-11
CVE-2023-4278 at NVD
6 known exploits for CVE-2023-4278
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2023-4278
WordPress Masterstudy LMS 3.0.17 Account Creation
Wordpress Masterstudy LMS Plugin - 3.0.17 - Unauthenticated Instructor Account Creation Exploit
Wordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account Creation
Exploit for CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation