CyberRota Analysis
AI-GeneratedThe MasterStudy LMS WordPress Plugin versions prior to 3.7.46 are vulnerable due to a lack of authorization checks, enabling unauthenticated attackers to access sensitive learning statistics of registered users, including course counts and quiz totals. This vulnerability poses a medium risk as it can lead to unauthorized data exposure. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.