Stylemixthemes
Stylemixthemes Masterstudy LMS: vulnerabilidades y CVE
Stylemixthemes Masterstudy LMS tiene 30 vulnerabilidades publicadas, 11 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE30
Últimos 12 meses11
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-88847 | Media (4.3) | 0.15% | — | 24 sept 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a… |
| CVE-2026-88846 | Media (5.3) | 0.18% | — | 24 sept 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing… |
| CVE-2026-81199 | Media (5.3) | 0.47% | — | 2 sept 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course… |
| CVE-2026-81200 | Baja (2.7) | 0.30% | — | 29 ago 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details,… |
| CVE-2026-78284 | Alta (8.6) | 0.53% | — | 24 ago 2026 | Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. |
| CVE-2026-28145 | Media (5.3) | 0.16% | — | 31 jul 2026 | Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39. |
| CVE-2026-57640 | Media (4.3) | 0.25% | — | 26 jun 2026 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions. |
| CVE-2026-42730 | Alta (8.5) | 0.36% | — | 27 may 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects… |
| CVE-2025-13766 | Media (5.4) | 0.17% | — | 6 ene 2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API… |
| CVE-2025-64366 | Alta (7.6) | 0.26% | — | 31 oct 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects… |
| CVE-2025-59575 | Media (4.9) | 0.31% | — | 22 oct 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects… |
| CVE-2025-59577 | Media (4.3) | 0.21% | — | 22 sept 2025 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Leveraging Race Conditions.This… |
| CVE-2025-59576 | Media (6.5) | 0.22% | — | 22 sept 2025 | Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from… |
| CVE-2025-54744 | Media (6.5) | 0.23% | — | 5 sept 2025 | Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from… |
| CVE-2025-32237 | Media (4.3) | 0.42% | — | 4 abr 2025 | Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from… |
| CVE-2025-32141 | Alta (8.8) | 0.68% | — | 4 abr 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows PHP Local File… |
| CVE-2024-37093 | Alta (8.8) | 0.21% | — | 2 ene 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through <= 3.2.1. |
| CVE-2024-37094 | Crítica (9.8) | 0.41% | — | 1 nov 2024 | Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12. |
| CVE-2024-5973 | Alta (8.8) | 0.49% | — | 22 jul 2024 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have. |
| CVE-2024-3942 | Media (5.4) | 0.38% | — | 2 may 2024 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in… |
| CVE-2024-3136 | Crítica (9.8) | 5.0% | — | 9 abr 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include… |
| CVE-2024-1904 | Media (4.3) | 0.47% | — | 9 abr 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible… |
| CVE-2024-2411 | Crítica (9.8) | 1.5% | — | 29 mar 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and… |
| CVE-2024-2409 | Crítica (9.8) | 0.83% | — | 29 mar 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by… |
| CVE-2024-2106 | Alta (7.5) | 0.80% | — | 13 mar 2024 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to… |
| CVE-2024-1512 | Crítica (9.8) | 78% | — | 17 feb 2024 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions… |
| CVE-2023-4278 | Alta (7.5) | 6.2% | — | 11 sept 2023 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or… |
| CVE-2023-35093 | Media (6.5) | 0.56% | — | 22 jun 2023 | Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of… |
| CVE-2023-35090 | Media (5.4) | 0.38% | — | 22 jun 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.7 versions. |
| CVE-2022-0441 | Crítica (9.8) | 85% | — | 7 mar 2022 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.