Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.15%—Stylemixthemes Masterstudy LMSAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to.
AplazadaMedia (5.3)0.18%—Stylemixthemes Masterstudy LMSAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has…
AplazadaMedia (5.3)0.47%—Stylemixthemes Masterstudy LMSAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
AplazadaBaja (2.7)0.30%—Stylemixthemes Masterstudy LMSAI29/8/202631/8/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.
AplazadaAlta (8.6)0.53%—Stylemixthemes Masterstudy LMSAI24/8/202626/8/2026
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
AplazadaMedia (5.3)0.16%—Stylemixthemes Masterstudy LMSAI31/7/202612/8/2026
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.
AplazadaMedia (4.3)0.25%—Stylemixthemes Masterstudy LMSAI26/6/202626/6/2026
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
AplazadaMedia (6.5)0.20%—Stylemixthemes Masterstudy LMS PROAI15/6/202630/9/2026
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.
AplazadaMedia (6.5)0.38%—Masterstudy LMS PRO PlusAI4/6/202622/7/2026
The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.5)0.36%—Stylemixthemes Masterstudy LMSAI27/5/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.7.29.
AplazadaMedia (5.4)0.17%—Stylemixthemes Masterstudy LMSAI6/1/202617/6/2026
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers,…
AplazadaAlta (7.5)0.36%—Stylemixthemes Masterstudy LMS PROAI18/12/202517/6/2026
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
AplazadaAlta (7.5)0.36%—Stylemixthemes Masterstudy LMS PROAI18/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
AplazadaAlta (7.6)0.26%—Stylemixthemes Masterstudy LMSAI31/10/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.6.27.
AplazadaMedia (5.4)0.22%—Stylemixthemes Masterstudy LMS PROAI29/10/202517/6/2026
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
AplazadaMedia (4.9)0.31%—Stylemixthemes Masterstudy LMSAI22/10/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS: from n/a through <= 3.6.20.
AplazadaMedia (4.3)0.21%—Stylemixthemes Masterstudy LMSAI22/9/202517/6/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Leveraging Race Conditions.This issue affects MasterStudy LMS: from n/a through <= 3.6.20.
AplazadaMedia (6.5)0.22%—Stylemixthemes Masterstudy LMSAI22/9/202517/6/2026
Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.6.20.
AplazadaMedia (6.5)0.23%—Stylemixthemes Masterstudy LMSAI5/9/202517/6/2026
Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.6.15.
AplazadaAlta (7.5)0.61%—Masterstudy LMS PROAI18/7/202517/6/2026
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload…
AplazadaMedia (4.3)0.42%—Stylemixthemes Masterstudy LMSAI4/4/202517/6/2026
Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.5.28.
AplazadaAlta (8.8)0.68%—Stylemixthemes Masterstudy LMSAI4/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows PHP Local File Inclusion.This issue affects MasterStudy LMS: from n/a through <= 3.5.28.
ModificadaAlta (8.8)0.21%—Stylemixthemes Masterstudy LMS2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through <= 3.2.1.
AnalizadaCrítica (9.8)0.41%—Stylemixthemes Masterstudy LMS1/11/202417/6/2026
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.
AplazadaMedia (5.3)0.36%—Stylemixthemes Masterstudy LMS StarterAI25/9/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.