google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

PRP: LFI in MasterStudy CVE-2024-3136 #495

Open RaulDoyensec opened 4 weeks ago

RaulDoyensec commented 4 weeks ago

Description

MasterStudy LMS is a plugin for WordPress with a new CVE found in 2024 (Local File Inclusion). I would like to write a plugin for this CVE as it could lead to Remote Code Execution from unauthenticated users.

References