Description
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
Published: 2025-12-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MasterStudy LMS Pro plugin for WordPress contains a missing authorization flaw that lets attackers delete content. The vulnerability stems from improperly constrained ACL checks, allowing unauthorized users to trigger deletion operations. An attacker who can reach the protected function can remove posts, pages, or other managed data, compromising data integrity and availability.

Affected Systems

StylemixThemes’ MasterStudy LMS Pro plugin, available for WordPress, is affected. Versions from the initial release through any version prior to 4.7.16 are vulnerable. The issue applies to installations on WordPress sites running these plugin versions.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk level, but the EPSS score of less than 1% suggests that attacks are currently rare. The vulnerability is not listed in the CISA KEV catalog, but the lack of an exploit probability does not preclude exploitation. The likely attack vector is from within a WordPress installation, requiring access to the plugin’s deletion interface, which may be reachable by users with sufficient privileges or through compromised credentials. An attacker with such access could delete arbitrary content without generating any alerts, resulting in loss of data and potential service disruption.

Generated by OpenCVE AI on April 29, 2026 at 18:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MasterStudy LMS Pro to version 4.7.16 or later.
  • If immediate update is not possible, disable the plugin or remove it to stop deletion functionality.
  • Review user roles and permissions in WordPress to ensure only trusted administrators have access to content editing features.

Generated by OpenCVE AI on April 29, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Stylemixthemes
Stylemixthemes masterstudy Lms
Wordpress
Wordpress wordpress
Vendors & Products Stylemixthemes
Stylemixthemes masterstudy Lms
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16.
Title WordPress MasterStudy LMS Pro plugin < 4.7.16 - Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References

Subscriptions

Stylemixthemes Masterstudy Lms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:10.851Z

Reserved: 2025-10-29T03:07:57.236Z

Link: CVE-2025-64214

cve-icon Vulnrichment

Updated: 2025-12-18T20:20:54.800Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:11.527

Modified: 2026-04-27T16:16:35.263

Link: CVE-2025-64214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:00:06Z

Weaknesses