İçeriğe atla
Noroxi

MasterStudy LMS WordPress Plugin – for Online Courses and Education

masterstudy-lms-learning-management-system · eklenti

MasterStudy LMS WordPress Plugin – for Online Courses and Education için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

28 bilinen açık

5 kritik · 9 kayıt giriş yapmadan sömürülebilir · 2 kayıt için istismar kodu yayımlanmış · son kayıt 24 Ağu 2026

wordpress.org'da yayında · son sürüm 3.7.52 · son güncelleme 24 Eyl 2026 · 10 bin+ kurulum

wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi

Güvenlik açıkları

  • CVE-2024-37094kimlik doğrulamasız≤ 3.2.12

    WordPress MasterStudy LMS plugin <= 3.2.12 - Broken Access Control vulnerability

    Kritik 9.8
  • CVE-2024-3136kimlik doğrulamasız≤ 3.3.3

    MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template

    Kritik 9.8
  • CVE-2024-2411kimlik doğrulamasız≤ 3.3.0

    MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal

    Kritik 9.8
  • CVE-2024-2409kimlik doğrulamasız≤ 3.3.1

    MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action

    Kritik 9.8
  • CVE-2024-1512kimlik doğrulamasız≤ 3.2.5

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection

    Kritik 9.8
  • CVE-2024-37093kimlik doğrulamasız · tıklama gerekir≤ 3.2.1

    WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability

    Yüksek 8.8
  • CVE-2025-32141giriş gerekir≤ 3.5.28

    WordPress MasterStudy LMS plugin <= 3.5.28 - Local File Inclusion vulnerability

    Yüksek 8.8
  • CVE-2026-78284kimlik doğrulamasız≤ 3.7.42

    WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability

    Yüksek 8.6
  • CVE-2026-40766abone+≤ 3.7.25

    WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability

    Yüksek 8.5
  • CVE-2026-42730giriş gerekir≤ 3.7.29

    WordPress MasterStudy LMS plugin <= 3.7.29 - SQL Injection vulnerability

    Yüksek 8.5
  • CVE-2025-64366yüksek yetki≤ 3.6.27

    WordPress MasterStudy LMS plugin <= 3.6.27 - SQL Injection vulnerability

    Yüksek 7.6
  • CVE-2024-2106kimlik doğrulamasız≤ 3.2.10

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route

    Yüksek 7.5
  • CVE-2026-73404abone+≤ 3.7.41

    WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2026-5060giriş gerekir≤ 3.7.23

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attach

    Orta 6.5
  • CVE-2026-57330abone+≤ 3.7.27

    WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2026-4817abone+≤ 3.7.25

    MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters

    Orta 6.5
  • CVE-2025-59576giriş gerekir≤ 3.6.20

    WordPress MasterStudy LMS Plugin <= 3.6.20 - Broken Access Control Vulnerability

    Orta 6.5
  • CVE-2025-54744giriş gerekir≤ 3.6.15

    WordPress MasterStudy LMS plugin <= 3.6.15 - Broken Access Control vulnerability

    Orta 6.5
  • CVE-2023-35093giriş gerekir≤ 3.0.8

    WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control

    Orta 6.5
  • CVE-2026-0559katılımcı+≤ 3.7.11

    MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_gr

    Orta 6.4
  • CVE-2026-68568abone+≤ 3.7.41

    WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability

    Orta 6.3
  • CVE-2023-35090katılımcı+≤ 3.0.7

    WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS)

    Orta 5.4
  • CVE-2026-28145kimlik doğrulamasız≤ 3.7.39

    WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability

    Orta 5.3
  • CVE-2025-59575yüksek yetki≤ 3.6.20

    WordPress MasterStudy LMS plugin <= 3.6.20 - Sensitive Data Exposure vulnerability

    Orta 4.9
  • CVE-2026-57640abone+≤ 3.7.30

    WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability

    Orta 4.3
  • CVE-2025-59577giriş gerekir≤ 3.6.20

    WordPress MasterStudy LMS Plugin <= 3.6.20 - Race Condition Vulnerability

    Orta 4.3
  • CVE-2025-32237giriş gerekir≤ 3.5.28

    WordPress MasterStudy LMS plugin <= 3.5.28 - Broken Access Control vulnerability

    Orta 4.3
  • CVE-2024-1904abone+≤ 3.2.13

    MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts

    Orta 4.3

Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).

← Dizine dön