The MasterStudy LMS WordPress plugin before version 2.7.6 fails to properly validate certain parameters during the user registration process. This flaw allows unauthenticated users to register new accounts with administrative privileges, bypassing intended access controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a small standalone Node.js exploit repository for CVE-2022-0441 affecting the MasterStudy LMS WordPress plugin up to 2.7.5. The repository contains three files: a README with usage and references, a minimal package.json declaring axios, and a single executable script, index.js, which is the exploit entry point. The exploit capability is privilege escalation via the plugin's registration flow. The script accepts a target base URL as a command-line argument, generates a random username and password, and sends a JSON POST request to the WordPress AJAX endpoint /wp-admin/admin-ajax.php with action=stm_lms_register and a required nonce parameter. The malicious part of the payload is the injected profile_default_fields_for_register.wp_capabilities.value.administrator=1 structure, which attempts to cause the newly registered account to be created with administrator privileges. Operationally, this is not just a detector: it performs account creation and prints the generated credentials when the server responds with status == "success". The exploit is somewhat manual because it relies on a valid stm_lms_register nonce; the code comments instruct the operator to retrieve it from the browser-side JavaScript variable stm_lms_nonces.stm_lms_register. That requirement means the exploit works only when the target exposes a usable registration page and nonce. Overall, the repository purpose is straightforward: automate exploitation of the vulnerable MasterStudy LMS registration handler to create an admin-level WordPress user on a remote target.
This repository contains a single Metasploit auxiliary module targeting a privilege escalation vulnerability (CVE-2022-0441) in the MasterStudy LMS WordPress plugin (versions prior to 2.7.6). The module allows an unauthenticated attacker to create a new administrator account on a vulnerable WordPress site by exploiting improper handling of registration requests in the plugin. The exploit works by first retrieving a registration nonce from the site's main page, then sending a crafted JSON POST request to the /wp-admin/admin-ajax.php endpoint with parameters that result in the creation of an admin-level user. The module supports user-supplied or auto-generated credentials for the new account. The code is written in Ruby and is designed to be run within the Metasploit framework. The repository is operational and provides a working exploit for the specified vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.