Description
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-02-14
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via plugin shortcode
Action: Apply Patch
AI Analysis

Impact

The MasterStudy LMS WordPress Plugin allows a stored XSS flaw in the stm_lms_courses_grid_display shortcode. The plugin fails to sanitize or escape user‑supplied attributes, meaning an authenticated contributor can insert arbitrary JavaScript that is persisted. When a page containing the affected shortcode is viewed, the injected script runs in the context of the visitor’s session. Based on this behavior, it is inferred that an attacker could hijack sessions, deface the site, or deliver other malicious payloads, as these are typical outcomes of stored XSS.

Affected Systems

WordPress sites that have the MasterStudy LMS WordPress Plugin – for Online Courses and Education installed, in any version up to and including 3.7.11. No specific patch version is indicated, so all installations of these versions are vulnerable until a newer plugin release is applied.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1 % signals a low probability of exploitation in the wild. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a contributor‑level account or higher; no remote public access is needed. Once a malicious script is stored via the shortcode, any user who visits a page containing that shortcode will execute the script in their browser session. The likely impacts on confidentiality and integrity of site content are inferred from typical stored XSS effects, potentially including session hijacking, defacement, or malicious payload delivery, but the exact scope cannot be determined from the available data.

Generated by OpenCVE AI on April 16, 2026 at 06:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MasterStudy LMS plugin to the latest version released by the vendor.
  • Remove or delete the stm_lms_courses_grid_display shortcode from any posts or pages where it is used, or replace it with a sanitized version.
  • Restrict contributor‑level or higher accounts until the plugin is fully updated, or consider temporarily removing editor roles for existing contributors.

Generated by OpenCVE AI on April 16, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Stylemix
Stylemix masterstudy Lms Wordpress Plugin – For Online Courses And Education
Wordpress
Wordpress wordpress
Vendors & Products Stylemix
Stylemix masterstudy Lms Wordpress Plugin – For Online Courses And Education
Wordpress
Wordpress wordpress

Sat, 14 Feb 2026 06:45:00 +0000

Type Values Removed Values Added
Description The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_courses_grid_display' shortcode in all versions up to, and including, 3.7.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Stylemix Masterstudy Lms Wordpress Plugin – For Online Courses And Education
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:16:07.986Z

Reserved: 2026-01-01T21:48:26.915Z

Link: CVE-2026-0559

cve-icon Vulnrichment

Updated: 2026-02-17T15:36:38.586Z

cve-icon NVD

Status : Deferred

Published: 2026-02-14T07:16:08.240

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-0559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T07:00:10Z

Weaknesses