VendorsStylemixThemesmasterstudy_lmsall versions
Vulnerabilities

StylemixThemes MasterStudy LMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2022-0441
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
Published 2022-03-07 · Modified
9.81 PoCEPSS 0.853
CVE-2024-1512
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
Published 2024-02-17 · Modified
9.8EPSS 0.776
CVE-2024-3136
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
Published 2024-04-09 · Modified
9.8EPSS 0.050
CVE-2024-2411
MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal
Published 2024-03-29 · Modified
9.8EPSS 0.015
CVE-2024-2409
MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
Published 2024-03-29 · Modified
9.8EPSS 0.008
CVE-2024-37094
WordPress MasterStudy LMS plugin <= 3.2.12 - Broken Access Control vulnerability
Published 2024-11-01 · Analyzed
9.8EPSS 0.004
CVE-2024-5973
MasterStudy LMS < 3.3.24 - Privilege Escalation to Instructor
Published 2024-07-22 · Modified
9.1EPSS 0.005
CVE-2024-37093
WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability
Published 2025-01-02 · Modified
8.8EPSS 0.002
CVE-2023-4278
MasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account Creation
Published 2023-09-11 · Modified
7.51 PoCEPSS 0.062
CVE-2024-2106
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route
Published 2024-03-13 · Modified
7.5EPSS 0.008
CVE-2023-35093
WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control
Published 2023-06-22 · Modified
6.5EPSS 0.006
CVE-2023-35090
WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS)
Published 2023-06-22 · Modified
6.5EPSS 0.004
CVE-2024-3942
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization
Published 2024-05-02 · Modified
6.3EPSS 0.004
CVE-2024-1904
MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts
Published 2024-04-09 · Modified
4.3EPSS 0.005