Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

MasterStudy LMS WordPress Plugin – for Online Courses and Education Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 31 vulnerability records associated with MasterStudy LMS WordPress Plugin – for Online Courses and Education, published between 2022 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

31Total records
5Critical
3High
23Medium
0Low
0Informational
31Patched records
0Currently marked unpatched
2022-02-01First disclosure
2026-07-28Latest disclosure
30 of 31CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202211 records
202355 records
20241010 records
202577 records
202688 records

Severity Breakdown

SeverityRecordsShare
Critical516.1%
High39.7%
Medium2374.2%

Vulnerability-Type Breakdown

Missing Authorization

11 records35.5%

First: 2023. Latest: 2026.

SQL Injection

5 records16.1%

First: 2024. Latest: 2026.

Privilege Escalation

4 records12.9%

First: 2022. Latest: 2024.

Cross-Site Scripting

4 records12.9%

First: 2023. Latest: 2026.

Other

4 records12.9%

First: 2024. Latest: 2025.

Information Disclosure

2 records6.5%

First: 2024. Latest: 2025.

CSRF

1 record3.2%

First: 2024. Latest: 2024.

Patch Status

Patched
31
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 3.7.24
  • 3.7.28
  • 3.7.31
  • 3.7.30
  • 3.7.26
  • 3.7.12
  • 3.7.7
  • 3.6.28
  • 3.6.21
  • 3.6.16
  • 3.5.29
  • 3.3.24
  • 3.2.2
  • 3.2.13
  • 3.3.9
  • 3.3.4
  • 3.3.1
  • 3.3.2
  • 3.3.0
  • 3.2.11
  • 3.2.6
  • 3.0.18
  • 2.8.0
  • 3.0.9
  • 2.9.35
  • 2.7.6

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-3.7.23MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment DeletionJuly 28, 20263.7.24Medium
*-3.7.27MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.27 - Authenticated (Subscriber+) Stored Cross-Site ScriptingJune 29, 20263.7.28Medium
*-3.7.30MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.30 - Missing AuthorizationJune 26, 20263.7.31Medium
*-3.7.29MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.29 - Authenticated (Subscriber+) SQL InjectionMay 24, 20263.7.30Medium
*-3.7.25MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL InjectionApril 21, 20263.7.26Medium
*-3.7.25MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' ParametersApril 16, 20263.7.26Medium
*-3.7.11MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' ShortcodeFebruary 13, 20263.7.12Medium
*-3.7.6MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and DeletionJanuary 5, 20263.7.7Medium
*-3.6.27MasterStudy LMS <= 3.6.27 - Authenticated (Instructor+) SQL InjectionOctober 23, 20253.6.28Medium
*-3.6.20MasterStudy LMS <= 3.6.20 - Authenticated (Instructor+) Sensitive Information ExposureOctober 16, 20253.6.21Medium
*-3.6.20MasterStudy LMS <= 3.6.20 - Missing AuthorizationSeptember 22, 20253.6.21Medium
*-3.6.20MasterStudy LMS <= 3.6.20 - Authenticated (Subscriber+) Race Condition to Multiple ReviewsSeptember 22, 20253.6.21Medium
*-3.6.15MasterStudy LMS <= 3.6.15 - Missing AuthorizationSeptember 3, 20253.6.16Medium
*-3.5.28MasterStudy LMS <= 3.5.28 - Missing AuthorizationApril 4, 20253.5.29Medium
*-3.5.28MasterStudy LMS <= 3.5.28 - Authenticated (Contributor+) Local File InclusionApril 4, 20253.5.29High
*-3.3.23MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.23 - Unauthenticated Limited Privilege Escalation to InstructorJuly 1, 20243.3.24High
*-3.2.1MasterStudy LMS <= 3.2.1 - Cross-Site Request ForgeryJune 20, 20243.2.2Medium
*-3.2.12MasterStudy LMS <= 3.2.12 - Missing AuthorizationJune 20, 20243.2.13Medium
*-3.3.8MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing AuthorizationApril 29, 20243.3.9Medium
*-3.3.3MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via templateApril 4, 20243.3.4Critical
*-3.3.0MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modalMarch 28, 20243.3.1Critical
*-3.3.1MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX ActionMarch 28, 20243.3.2Critical
*-3.2.13MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_postsMarch 15, 20243.3.0Medium
*-3.2.10MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST routeMarch 6, 20243.2.11Medium
*-3.2.5MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL InjectionFebruary 16, 20243.2.6Critical

Selected source records

Latest Records

MediumCVE-2026-5060

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion

Published: July 28, 2026

Affected versions
*-3.7.23
Patched versions
3.7.24
Original Wordfence record
MediumCVE-2026-57330

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Published: June 29, 2026

Affected versions
*-3.7.27
Patched versions
3.7.28
Original Wordfence record
MediumCVE-2026-57640

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.30 - Missing Authorization

Published: June 26, 2026

Affected versions
*-3.7.30
Patched versions
3.7.31
Original Wordfence record
MediumCVE-2026-42730

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.29 - Authenticated (Subscriber+) SQL Injection

Published: May 24, 2026

Affected versions
*-3.7.29
Patched versions
3.7.30
Original Wordfence record
MediumCVE-2026-40766

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL Injection

Published: April 21, 2026

Affected versions
*-3.7.25
Patched versions
3.7.26
Original Wordfence record
MediumCVE-2026-4817

MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters

Published: April 16, 2026

Affected versions
*-3.7.25
Patched versions
3.7.26
Original Wordfence record
MediumCVE-2026-0559

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode

Published: February 13, 2026

Affected versions
*-3.7.11
Patched versions
3.7.12
Original Wordfence record
MediumCVE-2025-13766

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion

Published: January 5, 2026

Affected versions
*-3.7.6
Patched versions
3.7.7
Original Wordfence record

Highest-Severity Records

CriticalCVE-2022-0441

MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation

Published: February 1, 2022

Affected versions
*-2.7.5
Patched versions
2.7.6
Original Wordfence record
CriticalCVE-2024-2409

MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action

Published: March 28, 2024

Affected versions
*-3.3.1
Patched versions
3.3.2
Original Wordfence record
CriticalCVE-2024-3136

MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template

Published: April 4, 2024

Affected versions
*-3.3.3
Patched versions
3.3.4
Original Wordfence record
CriticalCVE-2024-2411

MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal

Published: March 28, 2024

Affected versions
*-3.3.0
Patched versions
3.3.1
Original Wordfence record
CriticalCVE-2024-1512

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection

Published: February 16, 2024

Affected versions
*-3.2.5
Patched versions
3.2.6
Original Wordfence record
HighCVE-2025-32141

MasterStudy LMS <= 3.5.28 - Authenticated (Contributor+) Local File Inclusion

Published: April 4, 2025

Affected versions
*-3.5.28
Patched versions
3.5.29
Original Wordfence record
HighCVE-2024-5973

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.23 - Unauthenticated Limited Privilege Escalation to Instructor

Published: July 1, 2024

Affected versions
*-3.3.23
Patched versions
3.3.24
Original Wordfence record
HighCVE-2023-4278

MasterStudy LMS <= 3.0.17 - Privilege Escalation

Published: August 21, 2023

Affected versions
*-3.0.17
Patched versions
3.0.18
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory