CVE-2025-64215: WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerability
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MasterStudy LMS Pro Pluginto a version that resolves this vulnerability.Fixed in 4.7.16
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64215?
The severity of CVE-2025-64215 is medium, with a CVSS score of 6.5.
How does CVE-2025-64215 impact WordPress websites?
CVE-2025-64215 allows unauthorized access to functionalities within the MasterStudy LMS Pro plugin due to broken access control.
What version of MasterStudy LMS Pro is affected by CVE-2025-64215?
CVE-2025-64215 affects MasterStudy LMS Pro versions prior to 4.7.16.
How can I mitigate the risks related to CVE-2025-64215?
To mitigate the risks of CVE-2025-64215, update the MasterStudy LMS Pro plugin to version 4.7.16 or later.
Is user data at risk due to CVE-2025-64215?
CVE-2025-64215 does not expose user data, but it does allow unauthorized access to certain functionalities.