Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

63 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.2)0.12%—MasterstudylmsAI25/9/202625/9/2026
The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their…
AplazadaMedia (4.3)0.15%—Stylemixthemes Masterstudy LMSAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to.
AplazadaMedia (5.3)0.18%—Stylemixthemes Masterstudy LMSAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has…
AplazadaAlta (7.2)0.36%—MasterstudylmsAI24/9/202624/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an…
AplazadaMedia (4.3)0.20%—MasterstudylmsAI23/9/202623/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt…
AplazadaMedia (4.6)0.09%—MasterstudylmsAI23/9/202623/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be…
AplazadaBaja (2.7)0.30%—MasterstudylmsAI18/9/202618/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of…
AplazadaBaja (3.8)0.32%—MasterstudylmsAI18/9/202618/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and…
AplazadaMedia (5.3)0.47%—Stylemixthemes Masterstudy LMSAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
AplazadaBaja (3.8)0.32%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
AplazadaMedia (5.3)0.34%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft, pending and private) courses.
AplazadaBaja (2.7)0.30%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.
AplazadaMedia (5.3)0.34%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
AplazadaMedia (4.3)0.27%—MasterstudylmsAI2/9/20263/9/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
AplazadaBaja (2.7)0.30%—Stylemixthemes Masterstudy LMSAI29/8/202631/8/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.
AplazadaMedia (4.8)0.22%—MasterstudylmsAI29/8/202631/8/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token…
AplazadaAlta (8.6)0.53%—Stylemixthemes Masterstudy LMSAI24/8/202626/8/2026
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
AplazadaMedia (6.5)0.34%—MasterstudylmsAI18/8/202620/8/2026
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
AplazadaMedia (6.3)0.26%—Masterstudy LMSAI18/8/202620/8/2026
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
AplazadaMedia (5.3)0.16%—Stylemixthemes Masterstudy LMSAI31/7/202612/8/2026
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.
AplazadaMedia (6.5)0.39%—MasterstudylmsAI29/7/202630/7/2026
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to…
AplazadaMedia (6.5)0.22%—Masterstudy LMSAI29/6/202629/6/2026
Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.
AplazadaMedia (4.3)0.25%—Stylemixthemes Masterstudy LMSAI26/6/202626/6/2026
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
AplazadaAlta (8.5)0.36%—Masterstudy LMSAI15/6/202617/6/2026
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
AplazadaMedia (6.5)0.20%—Stylemixthemes Masterstudy LMS PROAI15/6/202630/9/2026
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.