Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MasterStudy LMS WordPress Plugin – for Online Courses and Education — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in MasterStudy LMS WordPress Plugin – for Online Courses and Education, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting MasterStudy LMS WordPress Plugin – for Online Courses and Education, categorized under common weakness types and tags. It aggregates reported issues spanning from early 2021 through the present day, providing a comprehensive historical view of security incidents related to this specific educational tool. Visitors can track vendor advisories to understand how the developer addresses reported flaws, gain deeper insight into specific weakness classes such as cross-site scripting or insecure direct object references, and look up the product’s vulnerability history to assess its long-term security posture. The collection includes details on severity levels, affected versions, and available patches, offering a clear picture of the risks associated with the plugin. By consolidating this information, the page aims to help administrators, developers, and security researchers make informed decisions about installation, updates, and mitigation strategies. The data is sourced from official vendor communications and publicly available security databases, ensuring accuracy and reliability. Users can filter results by severity or type to focus on critical issues, or browse chronologically to see the evolution of security practices over time. This resource does not provide recommendations or remediation steps but serves as a factual reference for understanding the threat landscape surrounding MasterStudy LMS. It is intended for informational purposes only and should be used in conjunction with professional security advice.

Vendor: StylemixThemes

CVE ID Title CVSS Severity Published
CVE-2026-5060 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion CWE-639 6.5 Medium 2026-07-29
CVE-2026-4817 MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters CWE-89 6.5 Medium 2026-04-17
CVE-2026-0559 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode CWE-79 6.4 Medium 2026-02-14
CVE-2025-13766 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion CWE-862 5.4 Medium 2026-01-06
CVE-2024-3942 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization CWE-862 6.3 Medium 2024-05-02
CVE-2024-3136 MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template CWE-98 9.8 Critical 2024-04-09
CVE-2024-1904 MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts CWE-862 4.3 Medium 2024-04-09
CVE-2024-2409 MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action CWE-266 9.8 Critical 2024-03-29
CVE-2024-2411 MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal CWE-98 9.8 Critical 2024-03-29
CVE-2024-2106 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route CWE-200 5.3 Medium 2024-03-13
CVE-2024-1512 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection CWE-89 9.8 Critical 2024-02-17
CVE-2023-35093 WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control CWE-862 6.5 Medium 2023-06-22
CVE-2023-35090 WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium 2023-06-22

All 13 known CVE vulnerabilities affecting MasterStudy LMS WordPress Plugin – for Online Courses and Education with full Chinese analysis, references, and POCs where available.