Executive brief
The MasterStudy LMS Pro Plus plugin for WordPress, which is used to manage online courses and e-learning platforms, contains a security flaw that allows authorized users with instructor-level access to access sensitive database information. By exploiting this vulnerability, an attacker could extract private data from the website's database, potentially compromising student or organizational information. This issue affects all versions of the plugin up to and including 4.8.20.
Technical details
The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping of the 'columns' parameter and a lack of proper preparation of the resulting SQL query. This vulnerability allows authenticated attackers with instructor-level privileges or higher to append malicious SQL commands to existing queries. By doing so, an attacker can extract sensitive data from the site's database. The attack is conducted over the network and does not require user interaction, though it does require valid 'instructor' credentials. The issue is present in all versions up to and including 4.8.20.
Affected products
- StylemixThemes MasterStudy LMS Pro Plus Up to and including 4.8.20
Timeline
- 2026-06-04: disclosed: CVE published to NVD dataset