Junglewise Threat Intelligence

CVE-2026-42730: Stylemix MasterStudy LMS SQL injection

CVE-2026-42730 · Severity: high · CVSS 8.5 · Published 2026-05-27

Executive brief

Stylemix MasterStudy LMS, a popular learning management system for WordPress, contains a security flaw that could allow users with basic account access to interfere with the site's database. An attacker could use this to steal sensitive information, modify site content, or gain unauthorized access to administrative data. This vulnerability is particularly dangerous as it can be targeted in automated mass-exploitation campaigns.

Technical details

A blind SQL injection vulnerability exists in the Stylemix MasterStudy LMS plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw is present in versions up to and including 3.7.29. An attacker with 'Subscriber' level privileges can exploit this vulnerability via network requests to interact directly with the underlying database. This could lead to the extraction of sensitive data (such as user credentials or configuration details) or the modification of database records. The issue has been addressed in version 3.7.30.

Affected products

  • StylemixThemes MasterStudy LMS <= 3.7.29

Timeline

  • 2026-04-24: other: Reported by researcher walow
  • 2026-05-24: advisory: Initial disclosure by Patchstack
  • 2026-05-27: disclosed: CVE published to NVD
  • 2026-05-24: patched: Patch released in version 3.7.30

References

Related threats