Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2023-06-22T11:07:21.020Z

Updated: 2024-08-02T16:23:59.003Z

Reserved: 2023-06-13T15:10:42.889Z

Link: CVE-2023-35093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-06-22T12:15:12.060

Modified: 2023-06-28T20:56:38.603

Link: CVE-2023-35093

cve-icon Redhat

No data.