Executive brief
MasterStudy LMS is a popular WordPress plugin used to create and manage online courses and learning platforms. A security vulnerability in versions 3.7.27 and earlier allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If a site administrator or another user views the affected content, the attacker could potentially hijack sessions, redirect visitors to malicious websites, or deface the platform.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the MasterStudy LMS plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows authenticated attackers with Subscriber-level privileges to inject arbitrary web scripts. Successful exploitation requires a victim (such as an administrator) to interact with the malicious payload, leading to script execution in the context of the victim's browser. This is classified as a stored XSS vulnerability with a scope change (S:C). The issue is resolved in version 3.7.28.
Affected products
- StylemixThemes MasterStudy LMS <= 3.7.27
Timeline
- 2026-04-15: disclosed: Reported by researcher endy
- 2026-06-29: advisory
- 2026-06-29: patched: Fixed in version 3.7.28