Description
WordPress Plugin MasterStudy LMS-for Online Courses and Education is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin MasterStudy LMS-for Online Courses and Education version 3.3.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.4 or latest
References
Related Vulnerabilities
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.16)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2018-20826)
WordPress Plugin Icons with Links Widget Cross-Site Scripting (1.2)
Apache Traffic Server Out-of-bounds Write Vulnerability (CVE-2021-35474)
Artifactory Incorrect Authorization Vulnerability (CVE-2021-45074)