StylemixThemes / Masterstudy Lms
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-28145 | WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability | MEDIUM | 5.3 | Jul 31, 2026 |
| CVE-2026-40766 | WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability | HIGH | 8.5 | Jun 15, 2026 |
| CVE-2024-37093 | WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability | HIGH | 8.8 | Jan 2, 2025 |
| CVE-2024-37094 | WordPress MasterStudy LMS plugin <= 3.2.12 - Broken Access Control vulnerability | CRITICAL | 9.8 | Nov 1, 2024 |
| CVE-2024-43990 | WordPress Masterstudy LMS Starter theme <= 1.1.8 - Sensitive Data Exposure vulnerability | MEDIUM | 5.3 | Sep 25, 2024 |
| CVE-2024-5973 | MasterStudy LMS < 3.3.24 - Privilege Escalation to Instructor | CRITICAL | 9.1 | Jul 22, 2024 |
| CVE-2024-3942 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization | MEDIUM | 6.3 | May 2, 2024 |
| CVE-2024-3136 | MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template | CRITICAL | 9.8 | Apr 9, 2024 |
| CVE-2024-1904 | MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts | MEDIUM | 4.3 | Apr 9, 2024 |
| CVE-2024-2411 | MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal | CRITICAL | 9.8 | Mar 29, 2024 |
| CVE-2024-2409 | MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action | CRITICAL | 9.8 | Mar 29, 2024 |
| CVE-2024-2106 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route | HIGH | 7.5 | Mar 13, 2024 |
| CVE-2024-1512 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection | CRITICAL | 9.8 | Feb 17, 2024 |
| CVE-2023-4278 | MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation | HIGH | 7.5 | Sep 11, 2023 |
| CVE-2023-35093 | WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control | MEDIUM | 6.5 | Jun 22, 2023 |
| CVE-2023-35090 | WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS) | MEDIUM | 6.5 | Jun 22, 2023 |
| CVE-2022-0441 | MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation | CRITICAL | 9.8 | Mar 7, 2022 |
Showing 1 to 15 of 15 CVEs