MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL Injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education
Minimum safe version
3.7.26
Update to 3.7.26 or later to address 30 fixable vulnerabilities
MasterStudy LMS <= 3.6.20 - Authenticated (Subscriber+) Race Condition to Multiple Reviews
MasterStudy LMS <= 3.6.20 - Missing Authorization
CVE-2026-4817
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode
CVE-2025-13766
CVE-2025-64366
CVE-2025-59575
CVE-2025-54744
CVE-2025-32141
CVE-2025-32237
CVE-2024-5973
CVE-2024-37093
CVE-2024-37094
CVE-2024-3942
CVE-2024-3136
CVE-2024-2411
CVE-2024-2409
CVE-2024-1904
CVE-2024-2106
CVE-2024-1512
WordPress MasterStudy LMS Plugin < 3.0.18 is vulnerable to Privilege Escalation
WordPress MasterStudy LMS Plugin <= 2.7.9 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-35090
CVE-2023-35093
WordPress MasterStudy LMS Plugin <= 2.9.34 is vulnerable to Broken Access Control
MasterStudy LMS WordPress Plugin <= 2.9.34 - Missing Authorization via wp_ajax_stm_wpcfto_get_settings
WordPress MasterStudy LMS plugin < 2.8.0 - Sensitive Information Disclosure vulnerability
WordPress MasterStudy LMS plugin < 2.8.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0441