Cyber Resilience

CVE-2023-4278

Stylemixthemes Masterstudy Lms ≤ 3.0.18

Public PoC
Published
11 September 2023
Modified
23 April 2025
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score 0.035 88th percentile
Risk Priority 71 floored blend · peak EPSS

Summary

CVE-2023-4278 is a high-severity an unspecified weakness vulnerability in Stylemixthemes Masterstudy Lms. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 12% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The MasterStudy LMS WordPress plugin before version 3.0.18 contains a missing authorization check during user registration that permits any unauthenticated visitor to create an account with the instructor role. The affected component is the registration workflow in this learning-management-system plugin for WordPress, which subsequently grants the newly created account the ability to publish courses and posts.

An attacker can exploit the flaw over the network without authentication or user interaction, achieving high-integrity impact by adding arbitrary course content or posts to the site. The CVSS 3.1 score of 7.5 reflects the combination of network accessibility, low attack complexity, and absence of required privileges.

Public references on WPScan and Packet Storm document the issue and include proof-of-concept material showing account creation, but do not detail additional mitigations beyond upgrading to 3.0.18 or later. The EPSS score has remained near 0.21–0.22 with no material rise after disclosure.

EU & UK References

Vulnerability Data

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.

CWE(s)
None listed

Related Threats

CVEs Like This One

CVE-2024-1512Same product: Stylemixthemes Masterstudy Lms
CVE-2022-0441Same product: Stylemixthemes Masterstudy Lms
CVE-2024-37093Same product: Stylemixthemes Masterstudy Lms
CVE-2023-35093Same product: Stylemixthemes Masterstudy Lms
CVE-2024-3942Same product: Stylemixthemes Masterstudy Lms
CVE-2023-35090Same product: Stylemixthemes Masterstudy Lms
CVE-2024-2411Same product: Stylemixthemes Masterstudy Lms
CVE-2024-2409Same product: Stylemixthemes Masterstudy Lms
CVE-2024-1904Same product: Stylemixthemes Masterstudy Lms
CVE-2024-3136Same product: Stylemixthemes Masterstudy Lms

Affected Assets

stylemixthemes
masterstudy lms
≤ 3.0.18

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References