Description
WordPress Plugin MasterStudy LMS-for Online Courses and Education is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently expose draft post titles and excerpts. WordPress Plugin MasterStudy LMS-for Online Courses and Education version 3.2.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.0 or latest
References
Related Vulnerabilities
ReviveAdserver URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-22873)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4608)
WordPress Plugin Social Review includes Backdoor [Only if downloaded via the vendor website] (1.0.8)
WordPress 2.0.5 Cross-Site Scripting Vulnerability (0.6.2 - 2.0.5)
Squid Incorrect Conversion between Numeric Types Vulnerability (CVE-2023-46848)