← WordPress Vulnerabilities
WordPress security by component

MasterStudy LMS

MasterStudy LMS is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jun 29, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: masterstudy-lms-learning-management-system

CVE-2026-57330: MasterStudy LMS: Cross-site scripting

MasterStudy LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.7.27.

PublishedJun 29, 2026
Known safe version3.7.28
Safe version
Jun 29, 2026 CVE-2026-57330
MasterStudy LMS: Cross-site scripting
MasterStudy LMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.7.27.
3.7.28
CVE6.5
NVDPending
Jun 26, 2026 CVE-2026-57640
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.7.30.
3.7.31
CVE4.3
NVDPending
Jun 15, 2026 CVE-2026-40766
MasterStudy LMS: SQL injection
MasterStudy LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.7.25.
3.7.26
CVE8.5
NVDPending
May 27, 2026 CVE-2026-42730
MasterStudy LMS: SQL injection
MasterStudy LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.7.29.
3.7.30
CVE8.5
NVDPending
Apr 17, 2026 CVE-2026-4817
MasterStudy LMS WordPress Plugin – for Online Courses and Education: SQL injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 3.7.25.
> 3.7.25
CVE6.5
NVDPending
Oct 31, 2025 CVE-2025-64366
MasterStudy LMS: SQL injection
MasterStudy LMS is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Oct 22, 2025 CVE-2025-59575
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.9
NVDPending
Sep 22, 2025 CVE-2025-59577
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Sep 22, 2025 CVE-2025-59576
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Sep 05, 2025 CVE-2025-54744
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Apr 04, 2025 CVE-2025-32237
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Apr 04, 2025 CVE-2025-32141
MasterStudy LMS: Filesystem traversal
MasterStudy LMS is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
Nov 01, 2024 CVE-2024-37094
MasterStudy LMS: A security weakness
MasterStudy LMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.2
NVD9.8
Jun 22, 2023 CVE-2023-35093
Masterstudy Lms Learning Management System: A security weakness
Masterstudy Lms Learning Management System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Jun 22, 2023 CVE-2023-35090
Masterstudy Lms Learning Management System: Cross-site scripting
Masterstudy Lms Learning Management System is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4