Record summary

CVE-2023-4278 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

MasterStudy LMS WordPress Plugin

Default status: unaffected

CVE ListBefore 3.0.18affected

Proofs of concept

2

Catalogued exploits

ExploitDBWordpress Plugin Masterstudy LMS - 3.0.17 - Unauthenticated Instructor Account CreationExploitDB exploitby Revan ArifioNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubrevan-ar/CVE-2023-4278Repository PoCby revan-arStars: 0Not analyzed3 files

25.1 KiB

GitHub

PoC details

References

3