Skip to content
Noroxi

MasterStudy LMS WordPress Plugin – for Online Courses and Education

masterstudy-lms-learning-management-system · plugin

Known security vulnerabilities for MasterStudy LMS WordPress Plugin – for Online Courses and Education. Find out in seconds which version runs on your site with WP Lens.

28 known vulnerabilities

5 critical · 9 exploitable without logging in · 2 with public exploit code · latest Aug 24, 2026

Listed on wordpress.org · latest 3.7.52 · last updated Sep 24, 2026 · 10K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2024-37094unauthenticated≤ 3.2.12

    WordPress MasterStudy LMS plugin <= 3.2.12 - Broken Access Control vulnerability

    Critical 9.8
  • CVE-2024-3136unauthenticated≤ 3.3.3

    MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template

    Critical 9.8
  • CVE-2024-2411unauthenticated≤ 3.3.0

    MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal

    Critical 9.8
  • CVE-2024-2409unauthenticated≤ 3.3.1

    MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action

    Critical 9.8
  • CVE-2024-1512unauthenticated≤ 3.2.5

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection

    Critical 9.8
  • CVE-2024-37093unauthenticated · needs a click≤ 3.2.1

    WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2025-32141login required≤ 3.5.28

    WordPress MasterStudy LMS plugin <= 3.5.28 - Local File Inclusion vulnerability

    High 8.8
  • CVE-2026-78284unauthenticated≤ 3.7.42

    WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability

    High 8.6
  • CVE-2026-40766subscriber+≤ 3.7.25

    WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability

    High 8.5
  • CVE-2026-42730login required≤ 3.7.29

    WordPress MasterStudy LMS plugin <= 3.7.29 - SQL Injection vulnerability

    High 8.5
  • CVE-2025-64366high privilege≤ 3.6.27

    WordPress MasterStudy LMS plugin <= 3.6.27 - SQL Injection vulnerability

    High 7.6
  • CVE-2024-2106unauthenticated≤ 3.2.10

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route

    High 7.5
  • CVE-2026-73404subscriber+≤ 3.7.41

    WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2026-5060login required≤ 3.7.23

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attach

    Medium 6.5
  • CVE-2026-57330subscriber+≤ 3.7.27

    WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulnerability

    Medium 6.5
  • CVE-2026-4817subscriber+≤ 3.7.25

    MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters

    Medium 6.5
  • CVE-2025-59576login required≤ 3.6.20

    WordPress MasterStudy LMS Plugin <= 3.6.20 - Broken Access Control Vulnerability

    Medium 6.5
  • CVE-2025-54744login required≤ 3.6.15

    WordPress MasterStudy LMS plugin <= 3.6.15 - Broken Access Control vulnerability

    Medium 6.5
  • CVE-2023-35093login required≤ 3.0.8

    WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control

    Medium 6.5
  • CVE-2026-0559contributor+≤ 3.7.11

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_gr

    Medium 6.4
  • CVE-2026-68568subscriber+≤ 3.7.41

    WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability

    Medium 6.3
  • CVE-2023-35090contributor+≤ 3.0.7

    WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS)

    Medium 5.4
  • CVE-2026-28145unauthenticated≤ 3.7.39

    WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2025-59575high privilege≤ 3.6.20

    WordPress MasterStudy LMS plugin <= 3.6.20 - Sensitive Data Exposure vulnerability

    Medium 4.9
  • CVE-2026-57640subscriber+≤ 3.7.30

    WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability

    Medium 4.3
  • CVE-2025-59577login required≤ 3.6.20

    WordPress MasterStudy LMS Plugin <= 3.6.20 - Race Condition Vulnerability

    Medium 4.3
  • CVE-2025-32237login required≤ 3.5.28

    WordPress MasterStudy LMS plugin <= 3.5.28 - Broken Access Control vulnerability

    Medium 4.3
  • CVE-2024-1904subscriber+≤ 3.2.13

    MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory