Junglewise Threat Intelligence

CVE-2025-64215: StylemixThemes MasterStudy LMS Pro missing authorization

CVE-2025-64215 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Vendors: StylemixThemes.

Executive brief

MasterStudy LMS Pro is a WordPress plugin used to create and manage online courses and learning platforms. A security flaw in this plugin allows unauthorized individuals to access and execute functions that should be restricted to administrators or specific users. This could allow an attacker to disrupt site operations or modify settings without permission, potentially impacting the integrity of the learning platform.

Technical details

A missing authorization vulnerability (CWE-862) exists in StylemixThemes MasterStudy LMS Pro versions prior to 4.7.16. The software fails to properly enforce Access Control Lists (ACLs) on certain internal functions, allowing unauthenticated remote attackers to execute logic that should be restricted. According to the CVSS vector, the attack is low complexity and requires no user interaction, potentially leading to unauthorized modifications or service disruption. Users should update to version 4.7.16 or later to remediate the issue.

Affected products

  • StylemixThemes MasterStudy LMS Pro before 4.7.16

Timeline

  • 2025-09-12: other: Reported by researcher Rafie Muhammad
  • 2026-04-23: patched: Patchstack published advisory and mitigation rules
  • 2026-06-15: disclosed: CVE published to NVD dataset

References