Impact
The vulnerability is a missing authorization flaw in the MasterStudy LMS Pro plugin that allows attackers to access features that are not properly protected by access control lists. This flaw can let an attacker use administrative or sensitive functionality without having the appropriate permissions, potentially exposing confidential learning management information and facilitating further exploitation. The weakness is classified under CWE-862, which denotes missing authorization or privilege escalation.
Affected Systems
StylemixThemes MasterStudy LMS Pro versions prior to 4.7.16 are affected. The plugin is used within WordPress sites to deliver learning management system services. No additional vendors or product versions are listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating a moderate severity level. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, and the issue is not listed in CISA's KEV catalog. Based on the description the likely attack vector is an authenticated or unauthenticated user sending requests to the plugin’s endpoints that lack proper ACL checks, but the exact conditions for exploitation are not detailed in the provided data.
OpenCVE Enrichment