目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

MasterStudy LMS WordPress Plugin – for Online Courses and Education 产品漏洞列表 / CVE 中文分析 13

MasterStudy LMS WordPress Plugin – for Online Courses and Education 产品相关 13 条漏洞,AI 中文标题与摘要、CVSS、POC 一站汇总。

MasterStudy LMS WordPress Plugin 是一款用于在线课程与教育的流行插件,本文档针对该产品的安全漏洞进行聚合分析。页面收录了涉及跨站脚本、越权访问及信息泄露等各类高危缺陷,时间跨度覆盖自产品发布以来的所有公开披露记录。读者可通过本索引追踪厂商的安全修复进度,深入理解特定版本中的架构弱点,并快速检索该插件的历史漏洞详情以评估系统风险。

ベンダー: StylemixThemes

CVE IDタイトルCVSS深刻度公開日
CVE-2026-5060 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion CWE-639 6.5 Medium2026-07-29
CVE-2026-4817 MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters CWE-89 6.5 Medium2026-04-17
CVE-2026-0559 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode CWE-79 6.4 Medium2026-02-14
CVE-2025-13766 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion CWE-862 5.4 Medium2026-01-06
CVE-2024-3942 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization CWE-862 6.3 Medium2024-05-02
CVE-2024-3136 MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template CWE-98 9.8 Critical2024-04-09
CVE-2024-1904 MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts CWE-862 4.3 Medium2024-04-09
CVE-2024-2409 MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action CWE-266 9.8 Critical2024-03-29
CVE-2024-2411 MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal CWE-98 9.8 Critical2024-03-29
CVE-2024-2106 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route CWE-200 5.3 Medium2024-03-13
CVE-2024-1512 MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection CWE-89 9.8 Critical2024-02-17
CVE-2023-35093 WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Broken Access Control CWE-862 6.5 Medium2023-06-22
CVE-2023-35090 WordPress MasterStudy LMS Plugin <= 3.0.8 is vulnerable to Cross Site Scripting (XSS) CWE-79 6.5 Medium2023-06-22

MasterStudy LMS WordPress Plugin – for Online Courses and Education 产品累计公开 13 条 CVE 漏洞,本页提供按时间倒序的完整列表,包含 CVSS、CWE、AI 中文摘要与可获取的 POC 链接。