Impact
The vulnerability is a missing authorization flaw in the Stylemix MasterStudy LMS WordPress plugin. Based on the description, it is inferred that an attacker who can reach the plugin’s administrative endpoints can bypass the intended role checks and gain unauthorized control over the learning management system. This flaw, classified as CWE‑862, may allow the compromise of confidential data, alteration of course content, or execution of other privileged actions within the hosting WordPress site.
Affected Systems
Stylemix’s MasterStudy LMS plugin, versions up to and including 3.5.28, is affected. Any WordPress installation that has this plugin installed at a version from the initial release through 3.5.28 is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% signals a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would most likely exploit the flaw by submitting crafted HTTP requests to the plugin’s admin or REST endpoints, relying on the absence of proper role checks. Although no current exploitation evidence is reported, the lack of authorization control could lead to privilege escalation within the WordPress environment.
OpenCVE Enrichment
EUVD