The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 10 Jun 2025 12:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Themegrill
         Themegrill masteriyo  | 
|
| CPEs | cpe:2.3:a:themegrill:masteriyo:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | 
        
        Masteriyo
         Masteriyo masteriyo  | 
    
        
        Themegrill
         Themegrill masteriyo  | 
Fri, 30 Aug 2024 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints. | The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students | 
Status: PUBLISHED
Assigner: WPScan
Published: 2023-07-31T09:37:36.423Z
Updated: 2024-08-30T13:34:18.185Z
Reserved: 2023-06-20T19:06:59.169Z
Link: CVE-2023-3345
Updated: 2024-08-02T06:55:02.693Z
Status : Modified
Published: 2023-07-31T10:15:10.653
Modified: 2025-06-10T11:56:01.460
Link: CVE-2023-3345
No data.