Extension WordPress
Vulnérabilités MasterStudy LMS WordPress Plugin – for Online Courses and Education, page 2
Cette page rassemble les failles publiées pour MasterStudy LMS WordPress Plugin – for Online Courses and Education, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de MasterStudy LMS WordPress Plugin – for Online Courses and Education
30 fiches
MasterStudy LMS <= 3.3.1 – Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes…
*-3.3.1
3.3.2
28/03/2024
MasterStudy LMS <= 3.2.13 – Missing Authorization to Sensitive Information Exposure in search_posts
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers,…
*-3.2.13
3.3.0
15/03/2024
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 – Basic Information Exposure via REST route
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered…
*-3.2.10
3.2.11
06/03/2024
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 – Unauthenticated SQL Injection
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5…
*-3.2.5
3.2.6
16/02/2024
MasterStudy LMS <= 3.0.17 – Privilege Escalation
The MasterStudy LMS plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.0.17. This makes it possible for unauthenticated attackers to register on the site as instructors, which would enable them to create…
*-3.0.17
3.0.18
21/08/2023
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.7.9
2.8.0
18/07/2023
MasterStudy LMS <= 3.0.8 – Missing Authorization to Course Category Creation
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_lms_create_term function in versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with…
*-3.0.8
3.0.9
15/06/2023
MasterStudy LMS <= 3.0.8 – Authenticated (Contributor+) Stored Cross-Site Scripting
The MasterStudy LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-3.0.8
3.0.9
15/06/2023
MasterStudy LMS WordPress Plugin <= 2.9.34 – Missing Authorization via wp_ajax_stm_wpcfto_get_settings
The MasterStudy LMS WordPress Plugin is vulnerable to unauthorized access of data due to a missing capability check on an anonymous function called by the stm_wpcfto_get_settings AJAX action in versions up to, and including, 2.9.345. This makes it…
*-2.9.34
2.9.35
03/04/2023
MasterStudy LMS < 2.7.6 – Unauthenticated Admin Account Creation
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
*-2.7.5
2.7.6
01/02/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.