WordPress security by component
MasterStudy LMS
Plugin description
MasterStudy LMS is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jun 29, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
masterstudy-lms-learning-management-systemLatest vulnerability
CVE-2026-57330: MasterStudy LMS: Cross-site scripting
MasterStudy LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.7.27.
| Safe version |
|
||
|---|---|---|---|
| Jun 29, 2026 |
CVE-2026-57330
MasterStudy LMS: Cross-site scripting
MasterStudy LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.7.27.
|
3.7.28 |
CVE6.5
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57640
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.7.30.
|
3.7.31 |
CVE4.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-40766
MasterStudy LMS: SQL injection
MasterStudy LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.7.25.
|
3.7.26 |
CVE8.5
NVDPending
|
| May 27, 2026 |
CVE-2026-42730
MasterStudy LMS: SQL injection
MasterStudy LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.7.29.
|
3.7.30 |
CVE8.5
NVDPending
|
| Apr 17, 2026 |
CVE-2026-4817
MasterStudy LMS WordPress Plugin – for Online Courses and Education: SQL injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.7.25.
|
> 3.7.25 |
CVE6.5
NVDPending
|
| Oct 31, 2025 |
CVE-2025-64366
MasterStudy LMS: SQL injection
MasterStudy LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| Oct 22, 2025 |
CVE-2025-59575
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Sep 22, 2025 |
CVE-2025-59577
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 22, 2025 |
CVE-2025-59576
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Sep 05, 2025 |
CVE-2025-54744
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32237
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32141
MasterStudy LMS: Filesystem traversal
MasterStudy LMS is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37094
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.2
NVD9.8
|
| Jun 22, 2023 |
CVE-2023-35093
Masterstudy Lms Learning Management System: A security weakness
Masterstudy Lms Learning Management System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Jun 22, 2023 |
CVE-2023-35090
Masterstudy Lms Learning Management System: Cross-site scripting
Masterstudy Lms Learning Management System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|