| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-4817 | MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Medium | 6.5 | 2026-04-17 01:24:37 | Deep Dive |
| CVE-2026-0559 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Medium | 6.4 | 2026-02-14 06:42:32 | Deep Dive |
| CVE-2025-13766 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Medium | 5.4 | 2026-01-06 08:21:48 | Deep Dive |
| CVE-2025-64214 | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Arbitrary Content Deletion vulnerability | StylemixThemes | MasterStudy LMS Pro | High | 7.5 | 2025-12-18 07:22:12 | Deep Dive |
| CVE-2025-64213 | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Sensitive Data Exposure vulnerability | StylemixThemes | MasterStudy LMS Pro | - | - | 2025-12-18 07:22:12 | Deep Dive |
| CVE-2025-64366 | WordPress MasterStudy LMS plugin <= 3.6.27 - SQL Injection vulnerability | Stylemix | MasterStudy LMS | High | 7.6 | 2025-10-31 11:42:39 | Deep Dive |
| CVE-2025-64212 | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability | StylemixThemes | MasterStudy LMS Pro | Medium | 5.4 | 2025-10-29 08:38:09 | Deep Dive |
| CVE-2025-59575 | WordPress MasterStudy LMS plugin <= 3.6.20 - Sensitive Data Exposure vulnerability | Stylemix | MasterStudy LMS | - | - | 2025-10-22 14:32:39 | Deep Dive |
| CVE-2025-59576 | WordPress MasterStudy LMS Plugin <= 3.6.20 - Broken Access Control Vulnerability | Stylemix | MasterStudy LMS | Medium | 6.5 | 2025-09-22 18:25:55 | Deep Dive |
| CVE-2025-59577 | WordPress MasterStudy LMS Plugin <= 3.6.20 - Race Condition Vulnerability | Stylemix | MasterStudy LMS | Medium | 4.3 | 2025-09-22 18:25:54 | Deep Dive |
| CVE-2025-54744 | WordPress MasterStudy LMS plugin <= 3.6.15 - Broken Access Control vulnerability | Stylemix | MasterStudy LMS | Medium | 6.5 | 2025-09-05 16:15:39 | Deep Dive |
| CVE-2025-7438 | MasterStudy LMS – Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File Upload | StylemixThemes | MasterStudy LMS Pro | High | 7.5 | 2025-07-18 06:45:33 | Deep Dive |
| CVE-2025-4800 | MasterStudy LMS Pro <= 4.7.0 - Authenticated (Subscriber+) Arbitrary File Upload | StylemixThemes | MasterStudy LMS Pro | High | 8.8 | 2025-05-28 05:24:22 | Deep Dive |
| CVE-2025-32237 | WordPress MasterStudy LMS plugin <= 3.5.28 - Broken Access Control vulnerability | Stylemix | MasterStudy LMS | Medium | 4.3 | 2025-04-04 15:59:21 | Deep Dive |
| CVE-2025-32141 | WordPress MasterStudy LMS plugin <= 3.5.28 - Local File Inclusion vulnerability | Stylemix | MasterStudy LMS | High | 8.8 | 2025-04-04 15:58:33 | Deep Dive |
| CVE-2024-37093 | WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability | Stylemix | MasterStudy LMS | Medium | 4.3 | 2025-01-02 12:00:40 | Deep Dive |
| CVE-2024-37094 | WordPress MasterStudy LMS plugin <= 3.2.12 - Broken Access Control vulnerability | StylemixThemes | MasterStudy LMS | High | 8.2 | 2024-11-01 13:52:59 | Deep Dive |
| CVE-2024-43990 | WordPress Masterstudy LMS Starter theme <= 1.1.8 - Sensitive Data Exposure vulnerability | StylemixThemes | Masterstudy LMS Starter | Medium | 5.3 | 2024-09-25 14:47:30 | Deep Dive |
| CVE-2024-5973 | MasterStudy LMS < 3.3.24 - Privilege Escalation to Instructor | Unknown | MasterStudy LMS WordPress Plugin | - | - | 2024-07-22 06:00:06 | Deep Dive |
| CVE-2024-3942 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization | stylemix | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Medium | 6.3 | 2024-05-02 16:52:11 | Deep Dive |