Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

StylemixThemes — Vulnerabilities & Security Advisories 62

Browse all 62 CVE security advisories affecting StylemixThemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

StylemixThemes operates as a prominent developer of WordPress themes and plugins, primarily targeting the e-commerce and lifestyle sectors through its extensive portfolio on marketplaces like ThemeForest. The company’s software has been associated with fifty recorded Common Vulnerabilities and Exposures (CVEs), reflecting significant security challenges in its codebase. Historically, these vulnerabilities frequently manifest as remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insufficient input validation and improper access controls within plugin architectures. While no single catastrophic data breach has been publicly attributed solely to StylemixThemes, the high volume of CVEs indicates systemic issues in their development and patching processes. Users are advised to exercise caution, ensuring all components are updated to mitigate risks associated with these known exploitation vectors.

CVE IDTitleCVSSSeverityPublished
CVE-2026-28145 WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability — MasterStudy LMSCWE-345 5.3 Medium2026-07-31
CVE-2026-14900 Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter — Cost Calculator Builder PROCWE-94 9.8 Critical2026-07-29
CVE-2026-27433 WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability — MotorsCWE-862 6.5 Medium2026-07-02
CVE-2026-27412 WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion vulnerability — Pearl - Corporate BusinessCWE-98 8.1 High2026-07-02
CVE-2025-68063 WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hockey theme <= 4.4.3 - Local File Inclusion vulnerability — Splash - Sport Club WordPress Theme for Basketball, Football, HockeyCWE-98 7.5 High2026-06-26
CVE-2026-54828 WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability — MotorsCWE-862 7.5 High2026-06-25
CVE-2026-54812 WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability — MotorsCWE-89 9.3 Critical2026-06-17
CVE-2026-54814 WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability — MotorsCWE-98 8.1 High2026-06-17
CVE-2026-40766 WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerability — MasterStudy LMSCWE-89 8.5 High2026-06-15
CVE-2026-39515 WordPress Motors plugin < 1.4.107 - Broken Access Control vulnerability — MotorsCWE-862 6.5 Medium2026-06-15
CVE-2025-64215 WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability — MasterStudy LMS ProCWE-862 6.5 Medium2026-06-15
CVE-2026-8653 MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' Parameter — MasterStudy LMS ProCWE-89 6.5 Medium2026-06-04
CVE-2025-64374 WordPress Motors theme <= 5.6.81 - Arbitrary File Upload vulnerability — MotorsCWE-434 9.9 Critical2025-12-18
CVE-2025-64214 WordPress MasterStudy LMS Pro plugin < 4.7.16 - Arbitrary Content Deletion vulnerability — MasterStudy LMS ProCWE-862 7.5 High2025-12-18
CVE-2025-64209 WordPress Masterstudy theme < 4.8.122 - Broken Access Control vulnerability — MasterstudyCWE-862 7.5 High2025-12-18
CVE-2025-64213 WordPress MasterStudy LMS Pro plugin < 4.7.16 - Sensitive Data Exposure vulnerability — MasterStudy LMS ProCWE-201 7.5 High2025-12-18
CVE-2025-64364 WordPress Masterstudy theme < 4.8.126 - Local File Inclusion vulnerability — MasterstudyCWE-98 7.5 High2025-10-31
CVE-2025-64361 WordPress Consulting Elementor Widgets plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability — Consulting Elementor WidgetsCWE-79 6.5 Medium2025-10-31
CVE-2025-64359 WordPress Consulting theme < 6.7.5 - Local File Inclusion vulnerability — ConsultingCWE-98 7.5 High2025-10-31
CVE-2025-64360 WordPress Consulting Elementor Widgets plugin <= 1.4.2 - Local File Inclusion vulnerability — Consulting Elementor WidgetsCWE-98 7.5 High2025-10-31
CVE-2025-64212 WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability — MasterStudy LMS ProCWE-862 5.4 Medium2025-10-29
CVE-2025-64210 WordPress Masterstudy Elementor Widgets plugin <= 1.2.4 - Broken Access Control vulnerability — Masterstudy Elementor WidgetsCWE-862 5.4 Medium2025-10-29
CVE-2025-64211 WordPress Masterstudy Elementor Widgets plugin <= 1.2.4 - Broken Access Control vulnerability — Masterstudy Elementor WidgetsCWE-862 5.3 Medium2025-10-29
CVE-2025-7438 MasterStudy LMS – Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File Upload — MasterStudy LMS ProCWE-434 7.5 High2025-07-18
CVE-2025-47586 WordPress Motors - Events plugin <= 1.4.7 - Unauthenticated Local File Inclusion vulnerability — Motors - EventsCWE-98 9.0 Critical2025-06-06
CVE-2025-4800 MasterStudy LMS Pro <= 4.7.0 - Authenticated (Subscriber+) Arbitrary File Upload — MasterStudy LMS ProCWE-434 8.8 High2025-05-28
CVE-2025-4322 Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover — Motors - Car Dealer, Rental & Listing WordPress themeCWE-620 9.8 Critical2025-05-20
CVE-2024-13738 Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution — Motors - Car Dealer, Rental & Listing WordPress themeCWE-94 7.3 High2025-05-03
CVE-2025-26986 WordPress Pearl Theme < 3.4.8 - Local File Inclusion vulnerability — Pearl - Corporate BusinessCWE-98 8.1 High2025-03-26
CVE-2024-11939 Cost Calculator Builder PRO <= 3.2.15 - Unauthenticated SQL Injection via data — Cost Calculator Builder PROCWE-89 7.5 High2025-01-08

This page lists every published CVE security advisory associated with StylemixThemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.