The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Themegrill
Themegrill masteriyo |
|
CPEs | cpe:2.3:a:themegrill:masteriyo:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Masteriyo
Masteriyo masteriyo |
Themegrill
Themegrill masteriyo |
Fri, 30 Aug 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints. | The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students |

Status: PUBLISHED
Assigner: WPScan
Published: 2023-07-31T09:37:36.423Z
Updated: 2024-08-30T13:34:18.185Z
Reserved: 2023-06-20T19:06:59.169Z
Link: CVE-2023-3345

Updated: 2024-08-02T06:55:02.693Z

Status : Modified
Published: 2023-07-31T10:15:10.653
Modified: 2025-06-10T11:56:01.460
Link: CVE-2023-3345

No data.