The Masteriyo LMS – eLearning and Online Course Builder for WordPress plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_logged_in_user() function in all versions up to, and including, 1.7.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
id: CVE-2024-24882
info:
name: Masteriyo LMS <= 1.7.2 - Unauthenticated Privilege Escalation
au
...