← back
CVE-2022-0441observed exploitationCWE-269

MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation

82Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 85%
from disclosure to weapon0 days
Published on NVDMar 7
1st PoCFeb 18
metasploitFeb 18
VulnCheckFeb 1
exploitation probability
85%top 1% of all CVEs
observed exploitation
yesVulnCheck
10 public exploit(s)
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.