Record summary

CVE-2024-2106 has a selected CVSS score of 5.3 (medium).

Description

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be used to help perform future attacks.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 13, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

MasterStudy LMS WordPress Plugin – for Online Courses and Education

Browse stylemix / MasterStudy LMS WordPress Plugin – for Online Courses and Education

Default status: unaffected

CVE ListThrough 3.2.10affected

Default status: unaffected

CVE ListThrough 3.2.10affected

References

5