CVE-2020-5667: Wantedlyinc Studyplus

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

Affected products

  • Wantedlyinc Studyplus: up to and including 6.3.7; up to and including 8.29.0

Published 2020-11-06. Last modified 2026-06-17.