MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.41 - Authenticated (Subscriber+) Privilege Escalation
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.7.41. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, wi...
- CVSS:
- 6.3
- Affected:
- up to 3.7.41
- Fixed in:
- 3.7.42
- Disclosed:
- Aug 18, 2026
CVE-2026-68568 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.41 - Missing Authorization
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.7.41. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 3.7.41
- Fixed in:
- 3.7.42
- Disclosed:
- Aug 18, 2026
CVE-2026-73404 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.39 - Missing Authorization
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.7.39. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.7.39
- Fixed in:
- 3.7.40
- Disclosed:
- Jul 31, 2026
CVE-2026-28145 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `...
- CVSS:
- 6.5
- Affected:
- up to 3.7.23
- Fixed in:
- 3.7.24
- Disclosed:
- Jul 28, 2026
CVE-2026-5060 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access...
- CVSS:
- 6.4
- Affected:
- up to 3.7.27
- Fixed in:
- 3.7.28
- Disclosed:
- Jun 29, 2026
CVE-2026-57330 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.30 - Missing Authorization
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.7.30. This makes it possible for authenticated attackers, with subscriber-level access and above, to perfo...
- CVSS:
- 4.3
- Affected:
- up to 3.7.30
- Fixed in:
- 3.7.31
- Disclosed:
- Jun 26, 2026
CVE-2026-57640 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.29 - Authenticated (Subscriber+) SQL Injection
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.29 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...
- CVSS:
- 6.5
- Affected:
- up to 3.7.29
- Fixed in:
- 3.7.30
- Disclosed:
- May 24, 2026
CVE-2026-42730 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL Injection
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...
- CVSS:
- 6.5
- Affected:
- up to 3.7.25
- Fixed in:
- 3.7.26
- Disclosed:
- Apr 21, 2026
CVE-2026-40766 on NVD →
MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters
medium
The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'order' and 'orderby' parameters in the /lms/stm-lms/order/items REST API endpoint in versions up to and including 3.7.25. This is due to insufficient input sanitization com...
- CVSS:
- 6.5
- Affected:
- up to 3.7.25
- Fixed in:
- 3.7.26
- Disclosed:
- Apr 16, 2026
CVE-2026-4817 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and output escaping on user supplied att...
- CVSS:
- 6.4
- Affected:
- up to 3.7.11
- Fixed in:
- 3.7.12
- Disclosed:
- Feb 13, 2026
CVE-2026-0559 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.7.7
unknown
[en] The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attack...
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.7
- Disclosed:
- Jan 6, 2026
CVE-2025-13766 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers,...
- CVSS:
- 5.4
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.7
- Disclosed:
- Jan 5, 2026
CVE-2025-13766 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] <= 3.6.27 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.6.27.
- Affected:
- up to 3.6.27
- Fix:
- No patched version reported
- Disclosed:
- Oct 31, 2025
CVE-2025-64366 on NVD →
MasterStudy LMS <= 3.6.27 - Authenticated (Instructor+) SQL Injection
medium
The MasterStudy LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.27 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with instructor-level access and...
- CVSS:
- 6.5
- Affected:
- up to 3.6.27
- Fixed in:
- 3.6.28
- Disclosed:
- Oct 23, 2025
CVE-2025-64366 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] <= 3.6.20 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS: from n/a through <= 3.6.20.
- Affected:
- up to 3.6.20
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-59575 on NVD →
MasterStudy LMS <= 3.6.20 - Authenticated (Instructor+) Sensitive Information Exposure
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.20. This makes it possible for authenticated attackers, with Custom-level access and above, to extract sensitive user or configuration da...
- CVSS:
- 4.3
- Affected:
- up to 3.6.20
- Fixed in:
- 3.6.21
- Disclosed:
- Oct 16, 2025
CVE-2025-59575 on NVD →
MasterStudy LMS <= 3.6.20 - Missing Authorization
medium
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in a function in versions up to, and including, 3.6.20. This makes it possible for authenticated attackers, with subscriber-level access and above, to view other user's order confirmation.
- CVSS:
- 4.3
- Affected:
- up to 3.6.20
- Fixed in:
- 3.6.21
- Disclosed:
- Sep 22, 2025
CVE-2025-59576 on NVD →
MasterStudy LMS <= 3.6.20 - Authenticated (Subscriber+) Race Condition to Multiple Reviews
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 3.6.20. This makes it possible for authenticated attackers, with Subscriber-level access and above, to leave multiple reviews on a course.
- CVSS:
- 4.3
- Affected:
- up to 3.6.20
- Fixed in:
- 3.6.21
- Disclosed:
- Sep 22, 2025
CVE-2025-59577 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.6.16
unknown
[en] Missing Authorization vulnerability in Stylemix MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.6.15.
- Affected:
- up to 3.6.16
- Fixed in:
- 3.6.16
- Disclosed:
- Sep 5, 2025
CVE-2025-54744 on NVD →
MasterStudy LMS <= 3.6.15 - Missing Authorization
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.6.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to p...
- CVSS:
- 4.3
- Affected:
- up to 3.6.15
- Fixed in:
- 3.6.16
- Disclosed:
- Sep 3, 2025
CVE-2025-54744 on NVD →
MasterStudy LMS <= 3.5.28 - Authenticated (Contributor+) Local File Inclusion
high
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.5.28. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those file...
- CVSS:
- 8.8
- Affected:
- up to 3.5.28
- Fixed in:
- 3.5.29
- Disclosed:
- Apr 4, 2025
CVE-2025-32141 on NVD →
MasterStudy LMS <= 3.5.28 - Missing Authorization
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, to p...
- CVSS:
- 4.3
- Affected:
- up to 3.5.28
- Fixed in:
- 3.5.29
- Disclosed:
- Apr 4, 2025
CVE-2025-32237 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.5.29
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix MasterStudy LMS allows PHP Local File Inclusion. This issue affects MasterStudy LMS: from n/a through 3.5.23.
- Affected:
- up to 3.5.29
- Fixed in:
- 3.5.29
- Disclosed:
- Apr 4, 2025
CVE-2025-32141 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.5.29
unknown
[en] Missing Authorization vulnerability in Stylemix MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.5.23.
- Affected:
- up to 3.5.29
- Fixed in:
- 3.5.29
- Disclosed:
- Apr 4, 2025
CVE-2025-32237 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.2.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes MasterStudy LMS allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through 3.2.1.
- Affected:
- up to 3.2.2
- Fixed in:
- 3.2.2
- Disclosed:
- Jan 2, 2025
CVE-2024-37093 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.2.13
unknown
[en] Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects MasterStudy LMS: from n/a through 3.2.12.
- Affected:
- up to 3.2.13
- Fixed in:
- 3.2.13
- Disclosed:
- Nov 1, 2024
CVE-2024-37094 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.3.24
unknown
[en] The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.
- Affected:
- up to 3.3.24
- Fixed in:
- 3.3.24
- Disclosed:
- Jul 22, 2024
CVE-2024-5973 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.23 - Unauthenticated Limited Privilege Escalation to Instructor
high
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.23. This is due to insufficient role restrictions when registering through the stm_lms_register AJAX endpoint. This makes it possible for u...
- CVSS:
- 7.3
- Affected:
- up to 3.3.23
- Fixed in:
- 3.3.24
- Disclosed:
- Jul 1, 2024
CVE-2024-5973 on NVD →
MasterStudy LMS <= 3.2.12 - Missing Authorization
medium
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_order and create_order functions in versions up to, and including, 3.2.12. This makes it possible for unauthenticated attackers to create and save orders.
- CVSS:
- 5.3
- Affected:
- up to 3.2.12
- Fixed in:
- 3.2.13
- Disclosed:
- Jun 20, 2024
CVE-2024-37094 on NVD →
MasterStudy LMS <= 3.2.1 - Cross-Site Request Forgery
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perfo...
- CVSS:
- 4.3
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.2
- Disclosed:
- Jun 20, 2024
CVE-2024-37093 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.3.9
unknown
[en] The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it possible for authenticated attackers, with...
- Affected:
- up to 3.3.9
- Fixed in:
- 3.3.9
- Disclosed:
- May 2, 2024
CVE-2024-3942 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it possible for authenticated attackers, with subsc...
- CVSS:
- 6.3
- Affected:
- up to 3.3.8
- Fixed in:
- 3.3.9
- Disclosed:
- Apr 29, 2024
CVE-2024-3942 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.3.4
unknown
[en] The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files....
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- Apr 9, 2024
CVE-2024-3136 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.3.0
unknown
[en] The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose draft post titles...
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Apr 9, 2024
CVE-2024-1904 on NVD →
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
critical
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 9.8
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.4
- Disclosed:
- Apr 4, 2024
CVE-2024-3136 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.3.1
unknown
[en] The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. Thi...
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.1
- Disclosed:
- Mar 29, 2024
CVE-2024-2411 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.3.2
unknown
[en] The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes it possible for unauthenticated atta...
- Affected:
- up to 3.3.2
- Fixed in:
- 3.3.2
- Disclosed:
- Mar 29, 2024
CVE-2024-2409 on NVD →
MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
critical
The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes it possible for unauthenticated attackers...
- CVSS:
- 9.8
- Affected:
- up to 3.3.1
- Fixed in:
- 3.3.2
- Disclosed:
- Mar 28, 2024
CVE-2024-2409 on NVD →
MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal
critical
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can...
- CVSS:
- 9.8
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.1
- Disclosed:
- Mar 28, 2024
CVE-2024-2411 on NVD →
MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts
medium
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose draft post titles and e...
- CVSS:
- 4.3
- Affected:
- up to 3.2.13
- Fixed in:
- 3.3.0
- Disclosed:
- Mar 15, 2024
CVE-2024-1904 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.2.11
unknown
[en] The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be u...
- Affected:
- up to 3.2.11
- Fixed in:
- 3.2.11
- Disclosed:
- Mar 13, 2024
CVE-2024-2106 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route
medium
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be used t...
- CVSS:
- 5.3
- Affected:
- up to 3.2.10
- Fixed in:
- 3.2.11
- Disclosed:
- Mar 6, 2024
CVE-2024-2106 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.2.6
unknown
[en] The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lac...
- Affected:
- up to 3.2.6
- Fixed in:
- 3.2.6
- Disclosed:
- Feb 17, 2024
CVE-2024-1512 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
critical
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of...
- CVSS:
- 9.8
- Affected:
- up to 3.2.5
- Fixed in:
- 3.2.6
- Disclosed:
- Feb 16, 2024
CVE-2024-1512 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.0.18
unknown
[en] The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.
- Affected:
- up to 3.0.18
- Fixed in:
- 3.0.18
- Disclosed:
- Sep 11, 2023
CVE-2023-4278 on NVD →
MasterStudy LMS <= 3.0.17 - Privilege Escalation
high
The MasterStudy LMS plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.0.17. This makes it possible for unauthenticated attackers to register on the site as instructors, which would enable them to create courses.
- CVSS:
- 7.3
- Affected:
- up to 3.0.17
- Fixed in:
- 3.0.18
- Disclosed:
- Aug 21, 2023
CVE-2023-4278 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.7.9
- Fixed in:
- 2.8.0
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.0.9
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.7 versions.
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
- Disclosed:
- Jun 22, 2023
CVE-2023-35090 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 3.0.9
unknown
[en] Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.9
- Disclosed:
- Jun 22, 2023
CVE-2023-35093 on NVD →
MasterStudy LMS <= 3.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The MasterStudy LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.9
- Disclosed:
- Jun 15, 2023
CVE-2023-35090 on NVD →
MasterStudy LMS <= 3.0.8 - Missing Authorization to Course Category Creation
medium
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_lms_create_term function in versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary cours...
- CVSS:
- 4.3
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.9
- Disclosed:
- Jun 15, 2023
CVE-2023-35093 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 2.9.35
unknown
Update the WordPress MasterStudy LMS plugin to the latest available version (at least 2.9.35).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress MasterStudy LMS Plugin. This vulnerability has been fixed in version 2.9.35.
- Affected:
- up to 2.9.35
- Fixed in:
- 2.9.35
- Disclosed:
- Apr 4, 2023
MasterStudy LMS WordPress Plugin <= 2.9.34 - Missing Authorization via wp_ajax_stm_wpcfto_get_settings
medium
The MasterStudy LMS WordPress Plugin is vulnerable to unauthorized access of data due to a missing capability check on an anonymous function called by the stm_wpcfto_get_settings AJAX action in versions up to, and including, 2.9.345. This makes it possible for authenticated attackers with subscriber-level permissions...
- CVSS:
- 4.3
- Affected:
- up to 2.9.34
- Fixed in:
- 2.9.35
- Disclosed:
- Apr 3, 2023
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 2.9.35
unknown
The MasterStudy LMS WordPress Plugin is vulnerable to unauthorized access of data due to a missing capability check on an anonymous function called by the stm_wpcfto_get_settings AJAX action in versions up to, and including, 2.9.345. This makes it possible for authenticated attackers with subscriber-level permissions...
- Affected:
- up to 2.9.35
- Fixed in:
- 2.9.35
- Disclosed:
- Apr 3, 2023
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 2.7.6
unknown
[en] The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
- Affected:
- up to 2.7.6
- Fixed in:
- 2.7.6
- Disclosed:
- Mar 7, 2022
CVE-2022-0441 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 2.8.0
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress MasterStudy LMS plugin (versions < 2.8.0).
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Feb 28, 2022
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 2.8.0
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress MasterStudy LMS plugin (versions < 2.8.0).
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
- Disclosed:
- Feb 28, 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
critical
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
- CVSS:
- 9.8
- Affected:
- up to 2.7.5
- Fixed in:
- 2.7.6
- Disclosed:
- Feb 1, 2022
CVE-2022-0441 on NVD →
MasterStudy LMS WordPress Plugin – for Online Courses and Education [masterstudy-lms-learning-management-system] < 2.8.0
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.8.0
- Fixed in:
- 2.8.0
CVE-2023-33999 on NVD →