Impact
The vulnerability is an improper neutralization of input during web page generation, allowing stored cross‑site scripting. A malicious actor can embed scripts that will execute in the browsers of any user who views a page generated by the MasterStudy LMS plugin. The description does not specify particular downstream effects, but stored scripts can be used for a range of attacks in the browser context.
Affected Systems
WordPress installations that use the StylemixThemes MasterStudy LMS plugin version 3.7.52 or earlier are affected. All releases prior to 3.7.53 are also vulnerable.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate risk. The EPSS score is not available, so the probability of exploitation is currently unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to inject malicious input via the plugin’s content fields; the likely attack vector is web‑based and probably requires an authenticated user with permission to add or edit content. This inference is drawn from typical stored XSS scenarios but is not explicitly stated in the advisory.
OpenCVE Enrichment