VYPR

MasterStudy LMS WordPress Plugin

by WordPress

CVEs (16)

  • CVE-2024-1512CriFeb 17, 2024
    risk 0.63cvss 9.8epss 0.78

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping…

  • CVE-2024-5973HigJul 22, 2024
    risk 0.57cvss 8.8epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

  • CVE-2023-4278HigSep 11, 2023
    risk 0.52cvss 7.5epss 0.06

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.

  • CVE-2026-88843HigSep 24, 2026
    risk 0.47cvss 7.2epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server.…

  • CVE-2024-3942MedMay 2, 2024
    risk 0.41cvss 6.3epss 0.00

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it…

  • CVE-2026-81199MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of…

  • CVE-2026-81195MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any…

  • CVE-2026-81342MedAug 29, 2026
    risk 0.31cvss 4.7epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

  • CVE-2026-81338MedSep 23, 2026
    risk 0.30cvss 4.6epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML…

  • CVE-2026-88847MedSep 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have…

  • CVE-2026-81339MedSep 23, 2026
    risk 0.28cvss 4.3epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and…

  • CVE-2025-13766MedJan 6, 2026
    risk 0.28cvss 5.4epss 0.00

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This…

  • CVE-2026-81340LowSep 18, 2026
    risk 0.25cvss 3.8epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment,…

  • CVE-2026-81198LowSep 2, 2026
    risk 0.25cvss 3.8epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses…

  • CVE-2026-88844LowSep 18, 2026
    risk 0.18cvss 2.7epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to…

  • CVE-2026-81200LowAug 29, 2026
    risk 0.18cvss 2.7epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by…