S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0441 Scanner

CVE-2022-0441 scanner - Unauthenticated Admin Account Creation vulnerability in MasterStudy LMS plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0441
9.8
CVSS

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
MasterStudy LMS – WordPress LMS Plugin
AFFECTED< 2.7.6SAFE ✓≥ 2.7.6
Updated Aug 22, 2026View on NVD →
Detail

MasterStudy LMS is a WordPress plugin that provides a comprehensive learning management system for teachers and educators to create and deliver online courses to students. It is an all-in-one platform that enables users to create quizzes, manage course materials, and track the progress of their learners. With its user-friendly interface, MasterStudy LMS offers a simple solution to both beginners and experts who wish to incorporate e-learning into their teaching and learning activities.

CVE-2022-0441 vulnerability is a critical security loophole discovered in the MasterStudy LMS WordPress plugin. The flaw occurs when certain parameters given during the registration process are not correctly validated, allowing unauthenticated users to register as an administrator. An attacker can exploit this vulnerability to gain full control over the website and execute malicious commands by registering with administrative privileges. With such power, an attacker can maliciously modify course materials, steal student data, and even take over the website.

Exploiting CVE-2022-0441 vulnerability can lead to dire consequences for website owners. As previously mentioned, attackers can gain administrative access, which means they can alter the website content and steal sensitive data. In addition, website owners stand to lose their existing users' trust, especially if their data falls into the wrong hands. Furthermore, the website's reputation could be severely harmed, affecting its ranking in search engines and reducing its visibility.

Finally, with s4e.io, you can quickly and easily learn about vulnerabilities in your digital assets. With their pro features, you can have access to real-time alerts, advanced vulnerability scanning, and detailed reports of any security risks identified in your systems. By subscribing to their services, you can have peace of mind knowing that your website is secured against any known vulnerabilities and that you will be notified of any threats discovered in your system.

 

REFERENCES

Solution Advice

To protect against CVE-2022-0441 vulnerability, website owners can take the following precautions:

  • Install the latest version of MasterStudy LMS, which includes the necessary security patches.
  • Use an excellent WordPress security plugin to monitor the website for any signs of unauthorized access or malicious activity.
  • Utilize two-factor authentication (2FA) to increase the security of the login process.
  • Limit the number of users with administrative access to the website.
  • Regularly update WordPress, the theme installed, and other plugins to ensure critical vulnerabilities are fixed.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0441 scanner - Unauthenticated Admin Account Creation vulnerability in MasterStudy LMS plugin for WordPress | S4E