CVE-2026-28145: WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability
Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State.
This issue affects MasterStudy LMS: from n/a through 3.7.39.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MasterStudy LMS pluginto a version that resolves this vulnerability.Fixed in 3.7.40
Event History
Frequently Asked Questions
What is CVE-2026-28145?
CVE-2026-28145 is a vulnerability in the StylemixThemes MasterStudy LMS plugin that allows for broken access control and manipulation of user states.
What is the severity of CVE-2026-28145?
CVE-2026-28145 has a medium severity level of 5.3 based on the CVSS scoring.
How do I fix CVE-2026-28145?
To fix CVE-2026-28145, update the MasterStudy LMS plugin to a version greater than 3.7.39.
Which versions of MasterStudy LMS are affected by CVE-2026-28145?
CVE-2026-28145 affects all versions of MasterStudy LMS from n/a up to and including 3.7.39.
What impact does CVE-2026-28145 have on user data?
CVE-2026-28145 can lead to unauthorized manipulation of user states, posing a risk to user data integrity.