packetstormsecurity.com
http://packetstormsecurity.com/files/175007/WordPress-Masterstudy-LMS-3.0.17-Account-Creation.html CVE-2023-4278
HIGH
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
Record summary
CVE-2023-4278 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MasterStudy LMS WordPress PluginDefault status: unaffected | CVE List | Before 3.0.18 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBWordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account CreationExploitDB exploitby Revan ArifioNot analyzed1 file
Repository PoCs
GitHubrevan-ar/CVE-2023-4278Repository PoCby revan-arStars: 0Not analyzed3 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-4278 wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/cb3173ec-9891-4bd8-9d05-24fe805b5235