7.5
CVE-2024-2106
- EPSS 1.88%
- Veröffentlicht 13.03.2024 16:15:31
- Zuletzt bearbeitet 22.01.2025 19:48:46
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be used to help perform future attacks.
Mögliche Gegenmaßnahme
MasterStudy LMS WordPress Plugin – for Online Courses and Education: Update to version 3.2.11, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
MasterStudy LMS WordPress Plugin – for Online Courses and Education
Version
*-3.2.10
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stylemixthemes ≫ Masterstudy Lms SwPlatformwordpress Version < 3.2.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.88% | 0.826 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|