Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.12% | — | MasterstudylmsAI | 25/9/2026 | 25/9/2026 | The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their… | |
| Aplazada | Media (4.3) | 0.15% | — | Stylemixthemes Masterstudy LMSAI | 24/9/2026 | 24/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to. | |
| Aplazada | Media (5.3) | 0.18% | — | Stylemixthemes Masterstudy LMSAI | 24/9/2026 | 24/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has… | |
| Aplazada | Alta (7.2) | 0.36% | — | MasterstudylmsAI | 24/9/2026 | 24/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an… | |
| Aplazada | Media (4.3) | 0.20% | — | MasterstudylmsAI | 23/9/2026 | 23/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt… | |
| Aplazada | Media (4.6) | 0.09% | — | MasterstudylmsAI | 23/9/2026 | 23/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be… | |
| Aplazada | Baja (2.7) | 0.30% | — | MasterstudylmsAI | 18/9/2026 | 18/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of… | |
| Aplazada | Baja (3.8) | 0.32% | — | MasterstudylmsAI | 18/9/2026 | 18/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and… | |
| Aplazada | Media (5.3) | 0.47% | — | Stylemixthemes Masterstudy LMSAI | 2/9/2026 | 3/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user. | |
| Aplazada | Baja (3.8) | 0.32% | — | MasterstudylmsAI | 2/9/2026 | 3/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors. | |
| Aplazada | Media (5.3) | 0.34% | — | MasterstudylmsAI | 2/9/2026 | 3/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses. | |
| Aplazada | Baja (2.7) | 0.30% | — | MasterstudylmsAI | 2/9/2026 | 3/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations. | |
| Aplazada | Media (5.3) | 0.34% | — | MasterstudylmsAI | 2/9/2026 | 3/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user. | |
| Aplazada | Media (4.3) | 0.27% | — | MasterstudylmsAI | 2/9/2026 | 3/9/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier. | |
| Aplazada | Baja (2.7) | 0.30% | — | Stylemixthemes Masterstudy LMSAI | 29/8/2026 | 31/8/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs. | |
| Aplazada | Media (4.8) | 0.22% | — | MasterstudylmsAI | 29/8/2026 | 31/8/2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token… | |
| Aplazada | Alta (8.6) | 0.53% | — | Stylemixthemes Masterstudy LMSAI | 24/8/2026 | 26/8/2026 | Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | MasterstudylmsAI | 18/8/2026 | 20/8/2026 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | |
| Aplazada | Media (6.3) | 0.26% | — | Masterstudy LMSAI | 18/8/2026 | 20/8/2026 | Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Stylemixthemes Masterstudy LMSAI | 31/7/2026 | 12/8/2026 | Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39. | |
| Aplazada | Media (6.5) | 0.39% | — | MasterstudylmsAI | 29/7/2026 | 30/7/2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to… | |
| Aplazada | Media (6.5) | 0.22% | — | Masterstudy LMSAI | 29/6/2026 | 29/6/2026 | Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Stylemixthemes Masterstudy LMSAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Masterstudy LMSAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions. | |
| Aplazada | Media (6.5) | 0.20% | — | Stylemixthemes Masterstudy LMS PROAI | 15/6/2026 | 30/9/2026 | Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16. |