Junglewise Threat Intelligence

CVE-2026-57330: StylemixThemes MasterStudy LMS Cross-Site Scripting via Subscriber role

CVE-2026-57330 · Severity: medium · CVSS 6.5 · Published 2026-06-29

Executive brief

MasterStudy LMS is a popular WordPress plugin used to create and manage online courses and learning platforms. A security vulnerability in versions 3.7.27 and earlier allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If a site administrator or another user views the affected content, the attacker could potentially hijack sessions, redirect visitors to malicious websites, or deface the platform.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the MasterStudy LMS plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows authenticated attackers with Subscriber-level privileges to inject arbitrary web scripts. Successful exploitation requires a victim (such as an administrator) to interact with the malicious payload, leading to script execution in the context of the victim's browser. This is classified as a stored XSS vulnerability with a scope change (S:C). The issue is resolved in version 3.7.28.

Affected products

  • StylemixThemes MasterStudy LMS <= 3.7.27

Timeline

  • 2026-04-15: disclosed: Reported by researcher endy
  • 2026-06-29: advisory
  • 2026-06-29: patched: Fixed in version 3.7.28

References

Related threats