Junglewise Threat Intelligence

CVE-2026-40766: StylemixThemes MasterStudy LMS SQL injection

CVE-2026-40766 · Severity: high · CVSS 8.5 · Published 2026-06-15

Executive brief

MasterStudy LMS is a popular WordPress plugin used to create and manage online courses and learning platforms. A security flaw allows logged-in users with basic 'Subscriber' accounts to perform unauthorized database queries. This could lead to the theft of sensitive student and instructor data, or disruption of the learning platform's operations.

Technical details

A SQL injection vulnerability exists in the MasterStudy LMS plugin for WordPress up to version 3.7.25. The flaw is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and can be exploited by an authenticated user with Subscriber-level privileges. By sending specially crafted requests to the server, an attacker can bypass intended query logic to extract sensitive information from the database. The vulnerability has been addressed in version 3.7.26.

Affected products

  • StylemixThemes MasterStudy LMS <= 3.7.25

Timeline

  • 2026-03-03: other: Vulnerability reported by Jakub Herman
  • 2026-04-21: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-04-21: patched: Version 3.7.26 released to address the issue

References

Related threats