Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 392 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.49% | — | Stylemixthemes Masterstudy LMS | 22/7/2024 | 17/6/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have. | |
| Modificada | Alta (8.8) | 0.53% | — | Stylemixthemes Consulting Elementor WidgetsStylemixthemes Masterstudy Elementor Widgets | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Masterstudy Elementor Widgets, StylemixThemes Consulting Elementor Widgets.This issue affects Masterstudy Elementor Widgets: from n/a through 1.2.2; Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Modificada | Media (5.4) | 0.38% | — | Stylemixthemes Masterstudy LMS | 2/5/2024 | 17/6/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 5.0% | — | Stylemixthemes Masterstudy LMS | 9/4/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This… | |
| Modificada | Media (4.3) | 0.47% | — | Stylemixthemes Masterstudy LMS | 9/4/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose draft post titles and… | |
| Modificada | Crítica (9.8) | 1.5% | — | Stylemixthemes Masterstudy LMS | 29/3/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This… | |
| Modificada | Crítica (9.8) | 0.83% | — | Stylemixthemes Masterstudy LMS | 29/3/2024 | 17/6/2026 | The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes it possible for unauthenticated… | |
| Modificada | Alta (7.5) | 0.80% | — | Stylemixthemes Masterstudy LMS | 13/3/2024 | 17/6/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be used… | |
| Modificada | Crítica (9.8) | 78% | — | Stylemixthemes Masterstudy LMS | 17/2/2024 | 17/6/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of… | |
| Modificada | Alta (7.5) | 6.2% | — | Stylemixthemes Masterstudy LMS | 11/9/2023 | 17/6/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts. | |
| Modificada | Media (6.5) | 0.56% | — | Stylemixthemes Masterstudy LMS | 22/6/2023 | 17/6/2026 | Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more. | |
| Modificada | Media (5.4) | 0.38% | — | Stylemixthemes Masterstudy LMS | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.7 versions. | |
| Modificada | Crítica (9.8) | 85% | — | Stylemixthemes Masterstudy LMS | 7/3/2022 | 17/6/2026 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin |