Impact
A missing authorization check in the Stylemix MasterStudy LMS WordPress plugin allows attackers to perform actions reserved for privileged roles, potentially exposing or altering sensitive data. This flaw is classified as a broken access control weakness (CWE-862).
Affected Systems
WordPress sites that use the Stylemix MasterStudy LMS plugin version 3.6.20 or earlier are affected; no other prerequisites are required beyond the plugin’s presence.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% shows a low likelihood of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector involves crafted HTTP requests by an authenticated user exploiting the lack of proper authorization checks, though an unauthenticated attacker could benefit if certain endpoints are exposed.
OpenCVE Enrichment
EUVD