9.8
CVSSv3

CVE-2022-0441

Published: 07/03/2022 Updated: 20/07/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The MasterStudy LMS WordPress plugin prior to 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

stylemixthemes masterstudy lms

Exploits

WordPress MasterStudy LMS plugin version 275 suffers from a missing access control allowing an unauthenticated party the ability to create an administrative account ...

Github Repositories

Checker for CVE-2022-0441

CVE-2022-0441 Checker for CVE-2022-0441 usage : python3 filepy change the target list

WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation

CVE-2022-0441 Title: WordPress Plugin MasterStudy LMS 275 - Unauthenticated Admin Account Creation Date: 16022022 Author: Numan Türle CVE: CVE-2022-0441 Software Link: wordpressorg/plugins/masterstudy-lms-learning-management-system/ Version: <276 Installation git clone githubcom/biulove0x/CVE-2022-0441

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

A vulnerability classified as critical was found in MasterStudy LMS Plugin up to 275 on WordPress (WordPress Plugin) This vulnerability affects an unknown part of the component New Account Handler The manipulation with an unknown input leads to a privileges management vulnerability The CWE definition for the vulnerability is CWE-269 The software does not properly assign,