S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jun 13, 2024

CVE-2024-3136 Scanner

CVE-2024-3136 scanner - Local File Inclusion (LFI) vulnerability in MasterStudy LMS plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-3136
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
MasterStudy LMS WordPress Plugin – for Online Courses and Educationby stylemix
0
masterstudy_lmsby stylemixthemes
AFFECTED< 3.3.4SAFE ✓≥ 3.3.4
Updated Aug 19, 2026View on NVD →
Detail

MasterStudy LMS is a popular learning management system plugin for WordPress, utilized by educators and institutions to create and manage online courses. It provides various tools for creating interactive lessons, quizzes, and multimedia content. Administrators and instructors use it to facilitate learning, track student progress, and enhance the educational experience. The software integrates seamlessly with WordPress, making it a flexible and widely adopted solution. Its user-friendly interface and robust features support a wide range of e-learning scenarios.

The Local File Inclusion (LFI) vulnerability in MasterStudy LMS plugin up to version 3.3.3 allows unauthenticated attackers to include and execute arbitrary files on the server. This vulnerability exists due to improper handling of the 'template' parameter. Exploiting this flaw can lead to unauthorized file access, data leakage, and potential code execution. The critical nature of this issue necessitates immediate attention and remediation.

The MasterStudy LMS plugin's 'template' parameter is vulnerable to Local File Inclusion (LFI) attacks. An attacker can exploit this by manipulating the 'template' parameter in HTTP requests, allowing the inclusion of arbitrary files from the server's file system. This can bypass access controls and execute PHP code from included files. The vulnerability affects all versions up to and including 3.3.3. The endpoint '/wp-admin/admin-ajax.php' and the parameter 'template' are specifically targeted in this attack vector.

Exploiting this vulnerability can lead to severe consequences, including unauthorized access to sensitive files, execution of arbitrary code on the server, and privilege escalation. Attackers can potentially gain control over the affected system, steal confidential data, and disrupt services. The ability to execute arbitrary PHP code can further be leveraged to install backdoors, exfiltrate data, and compromise the entire WordPress installation.

By using the S4E platform, you gain comprehensive protection for your digital assets. Our platform continuously scans for vulnerabilities, ensuring your systems remain secure against the latest threats. Detailed reports and actionable insights help you understand and mitigate risks effectively. Joining our platform provides you with the tools and support needed to maintain robust cybersecurity defenses. Secure your digital landscape today with S4E's expert solutions.

References:

Solution Advice
  • Upgrade MasterStudy LMS to version 3.3.4 or higher.
  • Implement strict input validation for all parameters.
  • Regularly update and patch WordPress plugins and themes.
  • Conduct security audits to identify and fix vulnerabilities.
  • Use web application firewalls to detect and block malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.