
वर्डप्रेस प्लगइन मास्टरस्टडी एलएमएस <= 3.0.17 - अप्रमाणित प्रशिक्षक खाता निर्माण।
![[vulnerable.png]](./vulnerable.png)
Exploit Title: Wordpress Plugin Masterstudy LMS <= 3.0.17 - Unauthenticated Instructor Account Creation
Google Dork: inurl:/user-public-account
Vendor Homepage: https://wordpress.org/plugins/masterstudy-lms-learning-management-system/
Software Link: https://stylemixthemes.com
Version: <= 3.0.17
CVE : CVE-2023-4278
$ git clone https://github.com/revan-ar/CVE-2023-4278
$ cd CVE-2023-4278/
$ python exploit.py