ZeroHour

CVE-2023-3345

PoC
CVSS 3.1
6.5 medium
EPSS
2%p79
Published
()
Modified
Description

The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students

Vendors
themegrill
Products
masteriyo
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.