Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical1
High0
Medium4
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2026-04-15

CVE-2026-0559 - For Online Courses And Education Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN For Online Courses And Education

CVE-2026-0559

MEDIUM CVSS 6.4 2026-02-14
Threat Entry Updated 2026-01-08

CVE-2025-13766 - For Online Courses And Education Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload or delete arbitrary media files, delete or modify posts, and create/manage course templates

PLUGIN For Online Courses And Education

CVE-2025-13766

MEDIUM CVSS 5.4 2026-01-06
Threat Entry Updated 2025-01-21

CVE-2024-3942 - For Online Courses And Education Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it possible for authenticated attackers, with subscriber level permissions and above, to read and modify content such as course questions, post titles, and taxonomies.

PLUGIN For Online Courses And Education

CVE-2024-3942

MEDIUM CVSS 6.3 2024-05-02
Threat Entry Updated 2025-01-22

CVE-2024-2106 - For Online Courses And Education Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be used to help perform future attacks.

PLUGIN For Online Courses And Education

CVE-2024-2106

MEDIUM CVSS 5.3 2024-03-13
Threat Entry Updated 2024-12-18

CVE-2024-1512 - For Online Courses And Education Plugin

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN For Online Courses And Education

CVE-2024-1512

CRITICAL CVSS 9.8 2024-02-17
Scroll to top