Home/Product/stylemixthemes masterstudy lms
Product

stylemixthemes masterstudy lms

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-37093
< 3.2.2
Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cros
4.3MEDIUM
CVE-2024-37094
< 3.2.13
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Secu
8.2HIGH
CVE-2024-5973
< 3.3.24
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts,
8.8HIGH
CVE-2024-3942
< 3.3.9
The MasterStudy LMS WordPress Plugin - for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access,
6.3MEDIUM
CVE-2024-3136
< 3.3.4
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the
9.8CRITICAL
CVE-2024-1904
< 3.3.0
The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sea
4.3MEDIUM
CVE-2024-2411
< 3.3.1
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the
9.8CRITICAL
CVE-2024-2409
< 3.3.2
The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This i
9.8CRITICAL
CVE-2024-2106
< 3.2.11
The MasterStudy LMS WordPress Plugin - for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure
5.3MEDIUM
CVE-2024-1512
<= 3.2.5
The MasterStudy LMS WordPress Plugin - for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Inje
9.8CRITICAL
CVE-2023-4278
< 3.0.18
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allow
7.5HIGH
CVE-2023-35093
<= 3.0.8
Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin - for Online Courses and Education plugin <
6.5MEDIUM
CVE-2023-35090
<= 3.0.7
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin - for Onli
6.5MEDIUM
CVE-2022-0441
< 2.7.6
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing
9.8CRITICAL
threatengine.sh