Vulnerabilities > Stylemixthemes > Masterstudy LMS

DATE CVE VULNERABILITY TITLE RISK
2025-01-02 CVE-2024-37093 Cross-Site Request Forgery (CSRF) vulnerability in Stylemixthemes Masterstudy LMS
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes MasterStudy LMS allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through 3.2.1.
network
low complexity
stylemixthemes CWE-352
8.8
2024-11-01 CVE-2024-37094 Unspecified vulnerability in Stylemixthemes Masterstudy LMS
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.
network
low complexity
stylemixthemes
critical
9.8
2024-07-22 CVE-2024-5973 Unspecified vulnerability in Stylemixthemes Masterstudy LMS
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.
network
low complexity
stylemixthemes
8.8
2024-05-02 CVE-2024-3942 Missing Authorization vulnerability in Stylemixthemes Masterstudy LMS
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8.
network
low complexity
stylemixthemes CWE-862
5.4
2024-03-13 CVE-2024-2106 Unspecified vulnerability in Stylemixthemes Masterstudy LMS
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10.
network
low complexity
stylemixthemes
7.5
2023-09-11 CVE-2023-4278 Unspecified vulnerability in Stylemixthemes Masterstudy LMS
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor.
network
low complexity
stylemixthemes
7.5
2023-06-22 CVE-2023-35093 Unspecified vulnerability in Stylemixthemes Masterstudy LMS
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.
network
low complexity
stylemixthemes
6.5
2023-06-22 CVE-2023-35090 Unspecified vulnerability in Stylemixthemes Masterstudy LMS
Auth.
network
low complexity
stylemixthemes
5.4
2022-03-07 CVE-2022-0441 Unspecified vulnerability in Stylemixthemes Masterstudy LMS
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
network
low complexity
stylemixthemes
critical
9.8