MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 85%
from disclosure to weapon0 days
Published on NVDMar 7
1st PoCFeb 18
metasploitFeb 18
VulnCheckFeb 1
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesVulnCheck
10 public exploit(s)
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
Affected products
Unknown · MasterStudy LMS – WordPress LMS Pluginpublic PoCs found — 10
exploitdbwww.exploit-db.com/exploits/50752unverifiedgithubgithub.com/biulove0x/CVE-2022-0441★ 6githubgithub.com/tegal1337/CVE-2022-0441★ 1githubgithub.com/SDragon1205/cve-2022-0441★ 1githubgithub.com/kyukazamiqq/CVE-2022-0441★ 0githubgithub.com/DappaNISM/CVE-2022-0441★ 0vulncheckvulncheck.com/xdb/c61b1da3217cunverifiedvulncheckvulncheck.com/xdb/5c3bd7ca7d81unverifiedvulncheckvulncheck.com/xdb/610484d97e27unverifiedvulncheckvulncheck.com/xdb/024c6c3af9baunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.