Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27361 | The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes it possible for unauthenticated attackers to register a user with administrator-level privileges when MasterStudy LMS Pro is installed and the LMS Forms Editor add-on is enabled. |
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action | |
| Weaknesses | CWE-266 |
Thu, 26 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:stylemixthemes:masterstudy_lms:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stylemixthemes
Stylemixthemes masterstudy Lms |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:stylemixthemes:masterstudy_lms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Stylemixthemes
Stylemixthemes masterstudy Lms |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:09:52.197Z
Reserved: 2024-03-12T21:35:10.961Z
Link: CVE-2024-2409
Updated: 2024-08-01T19:11:53.476Z
Status : Modified
Published: 2024-03-29T09:15:07.733
Modified: 2026-04-08T18:21:05.583
Link: CVE-2024-2409
No data.
OpenCVE Enrichment
No data.
EUVD