VYPR

MasterStudy LMS

by WordPress

Source repositories

CVEs (36)

  • CVE-2026-81197MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status, allowing unauthenticated users to read the titles and IDs of unpublished (draft,…

  • CVE-2026-28145MedJul 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.

  • CVE-2025-59575MedOct 22, 2025
    risk 0.32cvss 4.9epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS: from n/a through <= 3.6.20.

  • CVE-2026-81026MedAug 29, 2026
    risk 0.31cvss 4.8epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access…

  • CVE-2026-88845MedSep 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed…

  • CVE-2026-81194MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's…

  • CVE-2025-32237MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS: from n/a through <= 3.5.28.

  • CVE-2024-37093MedJan 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through <= 3.2.1.

  • CVE-2024-2106MedMar 13, 2024
    risk 0.28cvss 5.3epss 0.01

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's…

  • CVE-2026-88848MedSep 25, 2026
    risk 0.27cvss 4.2epss 0.00

    The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves…

  • CVE-2026-57640MedJun 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.

  • CVE-2025-59577MedSep 22, 2025
    risk 0.21cvss 4.3epss 0.00

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Leveraging Race Conditions.This issue affects MasterStudy LMS: from n/a through <= 3.6.20.

  • CVE-2024-1904MedApr 9, 2024
    risk 0.21cvss 4.3epss 0.00

    The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2026-81196LowSep 2, 2026
    risk 0.18cvss 2.7epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.

  • CVE-2026-5060MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the…

  • CVE-2026-57330MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.

Page 2 of 2