Impact
The Stylemix MasterStudy LMS plugin contains a missing authorization flaw that allows attackers to bypass intended access controls and view or modify restricted learning materials. This violation of policy grants unauthorized parties the ability to read confidential course content and potentially alter participant data or lesson structure, thereby impacting confidentiality and integrity within the LMS environment.
Affected Systems
Vulnerable installations of the Stylemix MasterStudy LMS WordPress plugin up to and including version 3.6.15 are affected. Any site running the plugin at or below this version falls under risk.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderately severe. The EPSS score of less than 1% indicates a low current probability of exploitation, and the issue is not listed in the CISA KEV catalog. While the precise attack vector is not detailed in the CVE description, it is reasonable to infer that remote actors could trigger the vulnerability through the plugin’s exposed interfaces. This means that an attacker with network access to the WordPress instance could potentially exploit the flaw. The lack of an exploit restriction means that the impact can be quickly realized without advanced prerequisites.
OpenCVE Enrichment