CVE-2022-0441

CRITICAL EXPLOITED NUCLEI

MasterStudy LMS <2.7.6 - Info Disclosure

Title source: llm

Description

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

Exploits (6)

nomisec WORKING POC 6 stars
by biulove0x · poc
https://github.com/biulove0x/CVE-2022-0441
nomisec WORKING POC 1 stars
by SDragon1205 · remote
https://github.com/SDragon1205/cve-2022-0441
nomisec WORKING POC 1 stars
by tegal1337 · remote
https://github.com/tegal1337/CVE-2022-0441
nomisec SCANNER
by kyukazamiqq · infoleak
https://github.com/kyukazamiqq/CVE-2022-0441
exploitdb WORKING POC
by numan türle · textwebappsphp
https://www.exploit-db.com/exploits/50752
metasploit WORKING POC
by h00die, Numan Türle · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/wp_masterstudy_privesc.rb

Nuclei Templates (1)

MasterStudy LMS <2.7.6 - Improper Access Control
CRITICALVERIFIEDby dwisiswant0,theamanrawat

Scores

CVSS v3 9.8
EPSS 0.8135
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2022-02-01

Classification

CWE
CWE-269
Status published

Affected Products (1)

stylemixthemes/masterstudy_lms < 2.7.6

Timeline

Published Mar 07, 2022
Tracked Since Feb 18, 2026