Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-06-17

CVE-2026-4817 - Masterstudy Lms Wordpress Plugin For Online Courses And Education

The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'order' and 'orderby' parameters in the /lms/stm-lms/order/items REST API endpoint in versions up to and including 3.7.25. This is due to insufficient input sanitization combined with a design flaw in the custom Query builder class that allows unquoted SQL injection in ORDER BY clauses. When the Query builder detects parentheses in the sort_by parameter, it treats the value as a SQL function and directly concatenates it into the…

PLUGIN Masterstudy Lms Wordpress Plugin For Online Courses And Education

CVE-2026-4817

MEDIUM CVSS 6.5 2026-04-17
Threat Entry Updated 2026-06-17

CVE-2026-0559 - MasterStudy LMS WordPress Plugin – for Online Courses and Education

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN MasterStudy LMS WordPress Plugin – for Online Courses and Education

CVE-2026-0559

MEDIUM CVSS 6.4 2026-02-14
Scroll to top