MasterStudy LMS WordPress Plugin – for Online Courses and Education
masterstudy-lms-learning-management-system · eklenti
MasterStudy LMS WordPress Plugin – for Online Courses and Education için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
28 bilinen açık
5 kritik · 9 kayıt giriş yapmadan sömürülebilir · 2 kayıt için istismar kodu yayımlanmış · son kayıt 24 Ağu 2026
wordpress.org'da yayında · son sürüm 3.7.52 · son güncelleme 24 Eyl 2026 · 10 bin+ kurulum
wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi
Güvenlik açıkları
- Kritik 9.8
CVE-2024-37094kimlik doğrulamasız≤ 3.2.12
WordPress MasterStudy LMS plugin <= 3.2.12 - Broken Access Control vulnerability
- Kritik 9.8
CVE-2024-3136kimlik doğrulamasız≤ 3.3.3
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
- Kritik 9.8
CVE-2024-2411kimlik doğrulamasız≤ 3.3.0
MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal
- Kritik 9.8
CVE-2024-2409kimlik doğrulamasız≤ 3.3.1
MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
- Kritik 9.8
CVE-2024-1512kimlik doğrulamasız≤ 3.2.5
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
- Yüksek 8.8
CVE-2024-37093kimlik doğrulamasız · tıklama gerekir≤ 3.2.1
WordPress MasterStudy LMS plugin <= 3.2.1 - Cross Site Request Forgery (CSRF) vulnerability
- Yüksek 8.8
CVE-2025-32141giriş gerekir≤ 3.5.28
WordPress MasterStudy LMS plugin <= 3.5.28 - Local File Inclusion vulnerability
- Yüksek 8.6
CVE-2026-78284kimlik doğrulamasız≤ 3.7.42
WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability
- Yüksek 8.5
CVE-2026-40766abone+≤ 3.7.25
WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability
- Yüksek 8.5
CVE-2026-42730giriş gerekir≤ 3.7.29
WordPress MasterStudy LMS plugin <= 3.7.29 - SQL Injection vulnerability
- Yüksek 7.6
CVE-2025-64366yüksek yetki≤ 3.6.27
WordPress MasterStudy LMS plugin <= 3.6.27 - SQL Injection vulnerability
- Yüksek 7.5
CVE-2024-2106kimlik doğrulamasız≤ 3.2.10
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route
- Orta 6.5
CVE-2026-73404abone+≤ 3.7.41
WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability
- Orta 6.5
CVE-2026-5060giriş gerekir≤ 3.7.23
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attach
- Orta 6.5
CVE-2026-57330abone+≤ 3.7.27
WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
CVE-2026-4817abone+≤ 3.7.25
MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters
- Orta 6.5
CVE-2025-59576giriş gerekir≤ 3.6.20
WordPress MasterStudy LMS Plugin <= 3.6.20 - Broken Access Control Vulnerability
- Orta 6.5
CVE-2025-54744giriş gerekir≤ 3.6.15
WordPress MasterStudy LMS plugin <= 3.6.15 - Broken Access Control vulnerability
- Orta 6.5
CVE-2023-35093giriş gerekir≤ 3.0.8
WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control
- Orta 6.4
CVE-2026-0559katılımcı+≤ 3.7.11
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_gr
- Orta 6.3
CVE-2026-68568abone+≤ 3.7.41
WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability
- Orta 5.4
CVE-2023-35090katılımcı+≤ 3.0.7
WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS)
- Orta 5.3
CVE-2026-28145kimlik doğrulamasız≤ 3.7.39
WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability
- Orta 4.9
CVE-2025-59575yüksek yetki≤ 3.6.20
WordPress MasterStudy LMS plugin <= 3.6.20 - Sensitive Data Exposure vulnerability
- Orta 4.3
CVE-2026-57640abone+≤ 3.7.30
WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability
- Orta 4.3
CVE-2025-59577giriş gerekir≤ 3.6.20
WordPress MasterStudy LMS Plugin <= 3.6.20 - Race Condition Vulnerability
- Orta 4.3
CVE-2025-32237giriş gerekir≤ 3.5.28
WordPress MasterStudy LMS plugin <= 3.5.28 - Broken Access Control vulnerability
- Orta 4.3
CVE-2024-1904abone+≤ 3.2.13
MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts
Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).