Description
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State.

This issue affects MasterStudy LMS: from n/a through 3.7.39.
Published: 2026-07-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an insufficient verification of data authenticity within the StylemixThemes MasterStudy LMS WordPress plugin. Attackers who can submit crafted requests may manipulate the authenticated user's state or impersonate other users, thereby elevating privileges and accessing or modifying content beyond the intended scope. This weakness is classified as CWE‑345 "Broken Access Control" and focuses on unauthorized privilege escalation; it does not directly disclose sensitive data.

Affected Systems

StylemixThemes MasterStudy LMS plugin versions up to and including 3.7.39 are affected. The flaw is present in all releases from the earliest shipped version through 3.7.39. WordPress core itself is not impacted; the issue lies entirely within the plugin's integration.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the moderate severity range, while an EPSS score of less than 1% indicates a low likelihood of observed exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be able to send crafted requests to the plugin, typically via the web interface or API endpoints, enabling manipulation of user state without needing privileged credentials. Given the limited exploitation probability and absence of publicly available exploit code, the risk is moderate but warrants timely remediation.

Generated by OpenCVE AI on August 3, 2026 at 09:56 UTC.

Remediation

Vendor Solution

Update the WordPress MasterStudy LMS plugin to the latest available version (at least 3.7.40).


OpenCVE Recommended Actions

  • Update MasterStudy LMS to version 3.7.40 or later, which contains the fix for the broken access control issue.
  • Review and tightly limit user roles and permissions on the site, ensuring that unnecessary privileges are removed to reduce the potential impact of user state manipulation.
  • Monitor for future updates from StylemixThemes and apply them promptly to maintain protection against this and other vulnerabilities.

Generated by OpenCVE AI on August 3, 2026 at 09:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Stylemixthemes
Stylemixthemes masterstudy Lms
Wordpress
Wordpress wordpress
Vendors & Products Stylemixthemes
Stylemixthemes masterstudy Lms
Wordpress
Wordpress wordpress

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.
Title WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Stylemixthemes Masterstudy Lms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-31T14:01:07.485Z

Reserved: 2026-02-25T12:14:24.000Z

Link: CVE-2026-28145

cve-icon Vulnrichment

Updated: 2026-07-31T14:01:04.630Z

cve-icon NVD

Status : Deferred

Published: 2026-07-31T14:16:49.967

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-28145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:00:12Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity