CVE-2022-0441
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
- Published
- Mar 7, 2022
- Updated
- Aug 2, 2024
- Assigning CNA
- WPScan
- Evidence observed
- Feb 18, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
Sources
6- CVE-2022-0441Exploit
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
- CVE-2022-0441Exploit
Mirrored from tegal1337/CVE-2022-0441
- CVE-2022-0441Exploit
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.