Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stylemix
Stylemix masterstudy Lms Wordpress Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Stylemix
Stylemix masterstudy Lms Wordpress Plugin Wordpress Wordpress wordpress |
Tue, 06 Jan 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload or delete arbitrary media files, delete or modify posts, and create/manage course templates | |
| Title | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:42:51.744Z
Reserved: 2025-11-27T16:40:43.878Z
Link: CVE-2025-13766
Updated: 2026-01-06T14:32:04.176Z
Status : Deferred
Published: 2026-01-06T09:15:53.983
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13766
No data.
OpenCVE Enrichment
Updated: 2026-04-22T20:30:26Z