Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Stylemix — Vulnerabilities & Security Advisories 79

Browse all 79 CVE security advisories affecting Stylemix. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Stylemix operates as a digital asset management and theme development platform, primarily serving web designers and content creators who require robust tools for managing media libraries and deploying WordPress themes. Security audits reveal a concerning history of vulnerabilities, with sixty-three Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve cross-site scripting (XSS) and remote code execution (RCE), often stemming from insufficient input validation and improper access controls. Privilege escalation remains a significant risk, allowing unauthorized users to manipulate system functions or access restricted data. While specific major incidents involving widespread exploitation are not widely publicized, the high volume of disclosed CVEs indicates persistent weaknesses in the software’s security architecture. Developers and administrators are advised to prioritize immediate patching and rigorous security testing to mitigate these known risks and protect associated web infrastructure from potential compromise.

CVE ID Title CVSS Severity Published
CVE-2026-73404 WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability — MasterStudy LMS CWE-862 6.5 Medium 2026-08-18
CVE-2026-68568 WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability — MasterStudy LMS CWE-266 6.3 Medium 2026-08-18
CVE-2026-66693 WordPress Motors plugin <= 1.4.113 - Broken Access Control vulnerability — Motors CWE-862 6.5 Medium 2026-08-13
CVE-2026-7753 Cost Calculator Builder <= 3.6.17 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure — Cost Calculator Builder CWE-862 6.5 Medium 2026-08-05
CVE-2026-5060 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion — MasterStudy LMS WordPress Plugin – for Online Courses and Education CWE-639 6.5 Medium 2026-07-29
CVE-2026-27392 WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability — uListing CWE-862 4.3 Medium 2026-07-23
CVE-2026-27391 WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability — uListing CWE-862 5.4 Medium 2026-07-23
CVE-2026-10865 Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys — Cost Calculator Builder CWE-200 5.3 Medium 2026-07-11
CVE-2026-13114 Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info — Motors – Car Dealership & Classified Listings Plugin CWE-79 7.2 High 2026-07-11
CVE-2026-12435 Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter — Motors – Car Dealership & Classified Listings Plugin CWE-862 4.3 Medium 2026-07-01
CVE-2026-57330 WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulnerability — MasterStudy LMS CWE-79 6.5 Medium 2026-06-29
CVE-2026-57640 WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability — MasterStudy LMS CWE-862 4.3 Medium 2026-06-26
CVE-2026-42730 WordPress MasterStudy LMS plugin <= 3.7.29 - SQL Injection vulnerability — MasterStudy LMS CWE-89 8.5 High 2026-05-27
CVE-2026-3892 Motors – Car Dealer, Classifieds & Listing <= 1.4.107 - Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' Parameter — Motors – Car Dealership & Classified Listings Plugin CWE-73 8.1 High 2026-05-14
CVE-2025-14755 Cost Calculator Builder <= 4.0.1 - Unauthenticated Price Manipulation and Insecure Direct Object Reference — Cost Calculator Builder CWE-862 5.3 Medium 2026-05-13
CVE-2026-1934 Motors – Car Dealership & Classified Listings Plugin <= 1.4.103 - Missing Authorization to Authenticated (Subscriber+) Payment Bypass via 'stm_payment_status' Parameter — Motors – Car Dealership & Classified Listings Plugin CWE-862 4.3 Medium 2026-05-12
CVE-2026-4817 MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters — MasterStudy LMS WordPress Plugin – for Online Courses and Education CWE-89 6.5 Medium 2026-04-17
CVE-2026-28078 WordPress uListing plugin <= 2.2.0 - Arbitrary File Download vulnerability — uListing CWE-22 4.9 Medium 2026-03-05
CVE-2026-28138 WordPress uListing plugin <= 2.2.0 - PHP Object Injection vulnerability — uListing CWE-502 7.2 High 2026-02-26
CVE-2026-0559 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode — MasterStudy LMS WordPress Plugin – for Online Courses and Education CWE-79 6.4 Medium 2026-02-14
CVE-2025-14757 Cost Calculator Builder <= 3.6.9 - Missing Authorization to Unauthenticated Payment Status Bypass — Cost Calculator Builder CWE-862 5.3 Medium 2026-01-16
CVE-2025-13766 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion — MasterStudy LMS WordPress Plugin – for Online Courses and Education CWE-862 5.4 Medium 2026-01-06
CVE-2025-12529 Cost Calculator Builder <= 3.6.3 - Unauthenticated Arbitrary File Deletion — Cost Calculator Builder CWE-73 8.8 High 2025-12-02
CVE-2025-62049 WordPress Cost Calculator Builder plugin <= 3.5.32 - Broken Access Control vulnerability — Cost Calculator Builder CWE-862 6.5 Medium 2025-11-06
CVE-2025-64366 WordPress MasterStudy LMS plugin <= 3.6.27 - SQL Injection vulnerability — MasterStudy LMS CWE-89 7.6 High 2025-10-31
CVE-2025-59575 WordPress MasterStudy LMS plugin <= 3.6.20 - Sensitive Data Exposure vulnerability — MasterStudy LMS CWE-497 4.9 Medium 2025-10-22
CVE-2025-10494 Motors – Car Dealership & Classified Listings Plugin <= 1.4.89 - Authenticated (Subscriber+) Arbitrary File Deletion — Motors – Car Dealership & Classified Listings Plugin CWE-73 8.1 High 2025-10-08
CVE-2025-9243 Cost Calculator Builder <= 3.5.32 - Authenticated (Subscriber+) Missing Authorization via get_cc_orders/update_order_status Functions — Cost Calculator Builder CWE-862 8.1 High 2025-10-04
CVE-2025-59576 WordPress MasterStudy LMS Plugin <= 3.6.20 - Broken Access Control Vulnerability — MasterStudy LMS CWE-862 6.5 Medium 2025-09-22
CVE-2025-59577 WordPress MasterStudy LMS Plugin <= 3.6.20 - Race Condition Vulnerability — MasterStudy LMS CWE-362 4.3 Medium 2025-09-22

This page lists every published CVE security advisory associated with Stylemix. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.