Masterstudy lms wordpress plugin – for online courses and education
This hub aggregates every CVE we track for Masterstudy lms wordpress plugin – for online courses and education, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
4
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM9CRITICAL4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
1
0
0
1
0
2024-092026-08
Latest CVEs
The 13 most recently published vulnerabilities affecting Masterstudy lms wordpress plugin – for online courses and education.
- CVE-2026-5060MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion6.5
- CVE-2026-4817MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters6.5
- CVE-2026-0559MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode6.4
- CVE-2025-13766MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion5.4
- CVE-2024-3942MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization6.3
- CVE-2024-3136MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template9.8
- CVE-2024-1904MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts4.3
- CVE-2024-2411MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal9.8
- CVE-2024-2409MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action9.8
- CVE-2024-2106MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route5.3
- CVE-2024-1512MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection9.8
- CVE-2023-35093WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control6.5
- CVE-2023-35090WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS)6.5
Product normalization is registry-driven with AI assist and human review. How it works