CVE-2024-24882
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
Record summary
CVE-2024-24882 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 5, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Masteriyo LMSBrowse Masteriyo / Masteriyo LMS | VulnCheck | Version data not supplied | |
Default status: unaffected | CVE List | Through 1.7.2 | affected |
masteriyoBrowse masteriyo / masteriyoDefault status: unknown | CVE List | Through 1.7.2 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALMasteriyo LMS <= 1.7.2 - Unauthenticated Privilege EscalationCVSS 9.8
The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_logged_in_user() function in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Impact
An unauthenticated attacker can escalate privileges and gain full administrator access.
Remediation
Update the Masteriyo LMS plugin to version 1.7.3 or later and ensure proper capability checks are enforced.
Source: ProjectDiscovery