Missing Authorization
11 records35.5%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 31 vulnerability records associated with MasterStudy LMS WordPress Plugin – for Online Courses and Education, published between 2022 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2022 | 1 | |
| 2023 | 5 | |
| 2024 | 10 | |
| 2025 | 7 | |
| 2026 | 8 |
| Severity | Records | Share |
|---|---|---|
| Critical | 5 | 16.1% |
| High | 3 | 9.7% |
| Medium | 23 | 74.2% |
First: 2023. Latest: 2026.
First: 2024. Latest: 2026.
First: 2022. Latest: 2024.
First: 2023. Latest: 2026.
First: 2024. Latest: 2025.
First: 2024. Latest: 2025.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.7.243.7.283.7.313.7.303.7.263.7.123.7.73.6.283.6.213.6.163.5.293.3.243.2.23.2.133.3.93.3.43.3.13.3.23.3.03.2.113.2.63.0.182.8.03.0.92.9.352.7.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.7.23 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion | July 28, 2026 | 3.7.24 | Medium |
*-3.7.27 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting | June 29, 2026 | 3.7.28 | Medium |
*-3.7.30 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.30 - Missing Authorization | June 26, 2026 | 3.7.31 | Medium |
*-3.7.29 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.29 - Authenticated (Subscriber+) SQL Injection | May 24, 2026 | 3.7.30 | Medium |
*-3.7.25 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL Injection | April 21, 2026 | 3.7.26 | Medium |
*-3.7.25 | MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters | April 16, 2026 | 3.7.26 | Medium |
*-3.7.11 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode | February 13, 2026 | 3.7.12 | Medium |
*-3.7.6 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion | January 5, 2026 | 3.7.7 | Medium |
*-3.6.27 | MasterStudy LMS <= 3.6.27 - Authenticated (Instructor+) SQL Injection | October 23, 2025 | 3.6.28 | Medium |
*-3.6.20 | MasterStudy LMS <= 3.6.20 - Authenticated (Instructor+) Sensitive Information Exposure | October 16, 2025 | 3.6.21 | Medium |
*-3.6.20 | MasterStudy LMS <= 3.6.20 - Missing Authorization | September 22, 2025 | 3.6.21 | Medium |
*-3.6.20 | MasterStudy LMS <= 3.6.20 - Authenticated (Subscriber+) Race Condition to Multiple Reviews | September 22, 2025 | 3.6.21 | Medium |
*-3.6.15 | MasterStudy LMS <= 3.6.15 - Missing Authorization | September 3, 2025 | 3.6.16 | Medium |
*-3.5.28 | MasterStudy LMS <= 3.5.28 - Missing Authorization | April 4, 2025 | 3.5.29 | Medium |
*-3.5.28 | MasterStudy LMS <= 3.5.28 - Authenticated (Contributor+) Local File Inclusion | April 4, 2025 | 3.5.29 | High |
*-3.3.23 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.23 - Unauthenticated Limited Privilege Escalation to Instructor | July 1, 2024 | 3.3.24 | High |
*-3.2.1 | MasterStudy LMS <= 3.2.1 - Cross-Site Request Forgery | June 20, 2024 | 3.2.2 | Medium |
*-3.2.12 | MasterStudy LMS <= 3.2.12 - Missing Authorization | June 20, 2024 | 3.2.13 | Medium |
*-3.3.8 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization | April 29, 2024 | 3.3.9 | Medium |
*-3.3.3 | MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template | April 4, 2024 | 3.3.4 | Critical |
*-3.3.0 | MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal | March 28, 2024 | 3.3.1 | Critical |
*-3.3.1 | MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action | March 28, 2024 | 3.3.2 | Critical |
*-3.2.13 | MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts | March 15, 2024 | 3.3.0 | Medium |
*-3.2.10 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route | March 6, 2024 | 3.2.11 | Medium |
*-3.2.5 | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection | February 16, 2024 | 3.2.6 | Critical |
Selected source records
Published: July 28, 2026
Published: June 29, 2026
Published: June 26, 2026
Published: May 24, 2026
Published: April 21, 2026
Published: April 16, 2026
Published: February 13, 2026
Published: January 5, 2026
Published: February 1, 2022
Published: March 28, 2024
Published: April 4, 2024
Published: March 28, 2024
Published: February 16, 2024
Published: April 4, 2025
Published: July 1, 2024
Published: August 21, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.