Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MasterStudy LMS — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in MasterStudy LMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the MasterStudy LMS plugin, a learning management system extension for WordPress. It collects reported flaws spanning multiple years of the product's lifecycle, covering a diverse range of severity levels and technical classifications. Readers can utilize this resource to track the vendor's advisory history, analyze specific weakness classes such as cross-site scripting or privilege escalation, and review the complete vulnerability timeline for this educational software component. The data provides a structured view of past security incidents, enabling developers and administrators to identify recurring patterns in the codebase. By examining these entries, users can assess the long-term security posture of the plugin and understand how previous issues were addressed through patches. This aggregation serves as a reference point for risk assessment, allowing stakeholders to evaluate the frequency and nature of defects introduced in various versions. The collection includes both high-impact critical vulnerabilities and lower-severity issues, offering a comprehensive perspective on the product's security evolution. Users should note that this list reflects publicly disclosed information and may not include all private or unpatched issues. The entries are organized to facilitate filtering by date, severity score, and vulnerability type, supporting targeted research into specific security concerns within the MasterStudy LMS ecosystem.

Vendor: StylemixThemes

CVE ID Title CVSS Severity Published
CVE-2026-88848 MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass 4.2 Medium 2026-09-25
CVE-2026-78284 WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability CWE-22 8.6 High 2026-08-24
CVE-2026-73404 WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-08-18
CVE-2026-68568 WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability CWE-266 6.3 Medium 2026-08-18
CVE-2026-28145 WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability CWE-345 5.3 Medium 2026-07-31
CVE-2026-57330 WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-06-29
CVE-2026-57640 WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability CWE-862 4.3 Medium 2026-06-26
CVE-2026-40766 WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability CWE-89 8.5 High 2026-06-15
CVE-2026-42730 WordPress MasterStudy LMS plugin <= 3.7.29 - SQL Injection vulnerability CWE-89 8.5 High 2026-05-27
CVE-2025-64366 WordPress MasterStudy LMS plugin <= 3.6.27 - SQL Injection vulnerability CWE-89 7.6 High 2025-10-31
CVE-2025-59575 WordPress MasterStudy LMS plugin <= 3.6.20 - Sensitive Data Exposure vulnerability CWE-497 4.9 Medium 2025-10-22
CVE-2025-59576 WordPress MasterStudy LMS Plugin <= 3.6.20 - Broken Access Control Vulnerability CWE-862 6.5 Medium 2025-09-22
CVE-2025-59577 WordPress MasterStudy LMS Plugin <= 3.6.20 - Race Condition Vulnerability CWE-362 4.3 Medium 2025-09-22
CVE-2025-54744 WordPress MasterStudy LMS plugin <= 3.6.15 - Broken Access Control vulnerability CWE-862 6.5 Medium 2025-09-05
CVE-2025-32237 WordPress MasterStudy LMS plugin <= 3.5.28 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-04-04
CVE-2025-32141 WordPress MasterStudy LMS plugin <= 3.5.28 - Local File Inclusion vulnerability CWE-98 8.8 High 2025-04-04
CVE-2024-37093 WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2025-01-02
CVE-2024-37094 WordPress MasterStudy LMS plugin <= 3.2.12 - Broken Access Control vulnerability CWE-862 8.2 High 2024-11-01

All 18 known CVE vulnerabilities affecting MasterStudy LMS with full Chinese analysis, references, and POCs where available.