Impact
The MasterStudy LMS Pro Plus plugin for WordPress contains a parameter‑based SQL injection flaw that allows an authenticated user with instructor‑level privileges or higher to modify the SQL query executed by the plugin. By supplying a crafted value to the 'columns' parameter, the attacker can inject additional SQL statements, enabling extraction of sensitive data such as user accounts, course content, or administrative credentials from the database.
Affected Systems
Affected systems are installations of the StylemixThemes MasterStudy LMS Pro WordPress plugin, versions up to and including 4.8.20. Any site running these versions of the plugin is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity when combined with the requirement for instructor‑level access. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to authenticate as an instructor or higher, which typically limits the exposed user base, but the ability to extract arbitrary database contents remains a serious concern when such access is compromised.
OpenCVE Enrichment