MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' Parameter
medium
The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentic...
- CVSS:
- 6.5
- Affected:
- up to 4.8.20
- Fixed in:
- 4.8.21
- Disclosed:
- Jun 3, 2026
CVE-2026-8653 on NVD →
MasterStudy LMS Pro < 4.7.16 - Missing Authorization
medium
The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 4.7.16. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.7.16
- Fixed in:
- 4.7.16
- Disclosed:
- Apr 23, 2026
CVE-2025-64215 on NVD →
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro] < 4.7.16
unknown
[en] Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
- Affected:
- up to 4.7.16
- Fixed in:
- 4.7.16
- Disclosed:
- Dec 18, 2025
CVE-2025-64214 on NVD →
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro] < 4.7.16
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
- Affected:
- up to 4.7.16
- Fixed in:
- 4.7.16
- Disclosed:
- Dec 18, 2025
CVE-2025-64213 on NVD →
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro] < 4.7.16
unknown
[en] Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
- Affected:
- up to 4.7.16
- Fixed in:
- 4.7.16
- Disclosed:
- Oct 29, 2025
CVE-2025-64212 on NVD →
MasterStudy LMS Pro < 4.7.16 - Missing Authorization to Unauthenticated Arbitrary Content Deletion
medium
The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in all versions up to 4.7.16 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary content.
- CVSS:
- 5.3
- Affected:
- up to 4.7.16
- Fixed in:
- 4.7.16
- Disclosed:
- Oct 12, 2025
CVE-2025-64214 on NVD →
MasterStudy LMS Pro < 4.7.16 - Missing Authorization
medium
The MasterStudy LMS Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 4.7.16 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.7.16
- Fixed in:
- 4.7.16
- Disclosed:
- Oct 12, 2025
CVE-2025-64212 on NVD →
MasterStudy LMS Pro < 4.7.16 - Authenticated (Subscriber+) Information Exposure
medium
The MasterStudy LMS Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 4.7.16 (exclusive). This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 4.7.16
- Fixed in:
- 4.7.16
- Disclosed:
- Oct 12, 2025
CVE-2025-64213 on NVD →
MasterStudy LMS – Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File Upload
high
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a...
- CVSS:
- 7.5
- Affected:
- up to 4.7.9
- Fixed in:
- 4.7.10
- Disclosed:
- Jul 17, 2025
CVE-2025-7438 on NVD →
MasterStudy LMS Pro <= 4.7.0 - Authenticated (Subscriber+) Arbitrary File Upload
high
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stm_lms_add_assignment_attachment function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload...
- CVSS:
- 8.8
- Affected:
- up to 4.7.0
- Fixed in:
- 4.7.1
- Disclosed:
- May 27, 2025
CVE-2025-4800 on NVD →
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro] < 4.7.1
unknown
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.1
CVE-2025-4800 on NVD →
MasterStudy LMS Pro [masterstudy-lms-learning-management-system-pro] < 4.7.10
unknown
- Affected:
- up to 4.7.10
- Fixed in:
- 4.7.10
CVE-2025-7438 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database