Access violation vulnerability in MasterStudy LMS WordPress Plugin – for Online Courses and Education 2.9.34

The MasterStudy LMS WordPress Plugin is vulnerable to unauthorized access of data. This means that people who have not been given permission can still access information. This is possible because a security check was not properly applied in versions up to, and including, 2.9.345. This security check is normally used to make sure that only certain people with the right permission level can access the data. In this case, any person who has at least a “subscriber” permission level can access the data.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.