The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 10 Jun 2025 12:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Themegrill Themegrill masteriyo | |
| CPEs | cpe:2.3:a:themegrill:masteriyo:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Masteriyo Masteriyo masteriyo | Themegrill Themegrill masteriyo | 
Fri, 30 Aug 2024 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The LMS by Masteriyo WordPress plugin before 1.6.8 does not properly safeguards sensitive user information, like other user's email addresses, making it possible for any students to leak them via some of the plugin's REST API endpoints. | The LMS by Masteriyo WordPress plugin before 1.6.8 does not have proper authorization in one some of its REST API endpoints, making it possible for any students to retrieve email addresses of other students | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-30T13:34:18.185Z
Reserved: 2023-06-20T19:06:59.169Z
Link: CVE-2023-3345
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T06:55:02.693Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-07-31T10:15:10.653
Modified: 2025-06-10T11:56:01.460
Link: CVE-2023-3345
 Redhat
                        Redhat
                    No data.