StylemixThemes Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with StylemixThemes products.
Products
- masterstudy_lms8 vulnerabilities
- MasterStudy LMS Pro7 vulnerabilities
- Consulting Elementor Widgets6 vulnerabilities
- Cost Calculator Builder PRO6 vulnerabilities
- Motors6 vulnerabilities
- uListing (WordPress plugin)6 vulnerabilities
- Masterstudy Elementor Widgets5 vulnerabilities
- consulting_elementor_widgets3 vulnerabilities
- MasterStudy LMS3 vulnerabilities
- Motors – Car Dealer, Classifieds & Listing3 vulnerabilities
- Consulting2 vulnerabilities
- Cost Calculator Builder2 vulnerabilities
- cost_calculator_builder2 vulnerabilities
- cost_calculator_builder_pro2 vulnerabilities
- eRoom – Zoom Meetings & Webinar (WordPress plugin)2 vulnerabilities
- Masterstudy2 vulnerabilities
- MasterStudy LMS WordPress Plugin – for Online Courses and Education2 vulnerabilities
- masterstudy_elementor_widgets2 vulnerabilities
- Motors - Car Dealer, Rental & Listing WordPress theme2 vulnerabilities
- Pearl - Corporate Business2 vulnerabilities
- Booking Calendar | Appointment Booking | BookIt1 vulnerability
- eRoom – Zoom Meetings & Webinar1 vulnerability
- GDPR Compliance & Cookie Consent1 vulnerability
- Masterstudy LMS Starter1 vulnerability
- MegaMenu1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-28145MEDIUM | WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerabilityInsufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39. CWE-345Jul 31, 2026 | CVSS5.3v3.1 | EPSS0.111% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-14900CRITICAL | Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' ParameterThe Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to PHP eval() inside js_to_php(), with the regex allow-list in evaluateFormula() only filtering alphanumeric tokens and leaving non-word punctuation characters intact. This makes it po… CWE-94Jul 29, 2026 | CVSS9.8v3.1 | EPSS0.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27433MEDIUM | WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in Motors <= 5.6.80 versions. CWE-862Jul 2, 2026 | CVSS6.5v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27412HIGH | WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion vulnerabilityUnauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. CWE-98Jul 2, 2026 | CVSS8.1v3.1 | EPSS0.274% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68063HIGH | WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hockey theme <= 4.4.3 - Local File Inclusion vulnerabilityContributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions. CWE-98Jun 26, 2026 | CVSS7.5v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-54828HIGH | WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerabilityUnauthenticated Broken Access Control in Motors <= 1.4.109 versions. CWE-862Jun 25, 2026 | CVSS7.5v3.1 | EPSS0.238% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-54812CRITICAL | WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109. CWE-89Jun 17, 2026 | CVSS9.3v3.1 | EPSS0.283% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-54814HIGH | WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerabilityImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109. CWE-98Jun 17, 2026 | CVSS8.1v3.1 | EPSS0.327% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40766HIGH | WordPress MasterStudy LMS plugin <= 3.7.25 - SQL Injection vulnerabilitySubscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions. CWE-89Jun 15, 2026 | CVSS8.5v3.1 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-39515MEDIUM | WordPress Motors plugin < 1.4.107 - Broken Access Control vulnerabilitySubscriber Broken Access Control in Motors < 1.4.107 versions. CWE-862Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.352% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64215MEDIUM | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerabilityMissing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16. CWE-862Jun 15, 2026 | CVSS6.5v3.1 | EPSS0.196% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8653MEDIUM | MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' ParameterThe MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with instructor-level access or above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the dat… CWE-89Jun 4, 2026 | CVSS6.5v3.1 | EPSS0.217% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64374CRITICAL | WordPress Motors theme <= 5.6.81 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through <= 5.6.81. CWE-434Dec 18, 2025 | CVSS9.9v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64214HIGH | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Arbitrary Content Deletion vulnerabilityMissing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16. CWE-862Dec 18, 2025 | CVSS7.5v3.1 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64213HIGH | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Sensitive Data Exposure vulnerabilityInsertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Retrieve Embedded Sensitive Data.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16. CWE-201Dec 18, 2025 | CVSS7.5v3.1 | EPSS0.321% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64209HIGH | WordPress Masterstudy theme < 4.8.122 - Broken Access Control vulnerabilityMissing Authorization vulnerability in StylemixThemes Masterstudy masterstudy allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy: from n/a through < 4.8.122. CWE-862Dec 18, 2025 | CVSS7.5v3.1 | EPSS0.304% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64364HIGH | WordPress Masterstudy theme < 4.8.126 - Local File Inclusion vulnerabilityImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Masterstudy masterstudy allows PHP Local File Inclusion.This issue affects Masterstudy: from n/a through < 4.8.126. CWE-98Oct 31, 2025 | CVSS7.5v3.1 | EPSS0.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64361MEDIUM | WordPress Consulting Elementor Widgets plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows DOM-Based XSS.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2. CWE-79Oct 31, 2025 | CVSS6.5v3.1 | EPSS0.154% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64360HIGH | WordPress Consulting Elementor Widgets plugin <= 1.4.2 - Local File Inclusion vulnerabilityImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2. CWE-98Oct 31, 2025 | CVSS7.5v3.1 | EPSS0.361% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64359HIGH | WordPress Consulting theme < 6.7.5 - Local File Inclusion vulnerabilityImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through < 6.7.5. CWE-98Oct 31, 2025 | CVSS7.5v3.1 | EPSS0.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64212MEDIUM | WordPress MasterStudy LMS Pro plugin < 4.7.16 - Broken Access Control vulnerabilityMissing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro masterstudy-lms-learning-management-system-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MasterStudy LMS Pro: from n/a through < 4.7.16. CWE-862Oct 29, 2025 | CVSS5.4v3.1 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64211MEDIUM | WordPress Masterstudy Elementor Widgets plugin <= 1.2.4 - Broken Access Control vulnerabilityMissing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy Elementor Widgets: from n/a through <= 1.2.4. CWE-862Oct 29, 2025 | CVSS5.3v3.1 | EPSS0.209% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64210MEDIUM | WordPress Masterstudy Elementor Widgets plugin <= 1.2.4 - Broken Access Control vulnerabilityMissing Authorization vulnerability in StylemixThemes Masterstudy Elementor Widgets masterstudy-elementor-widgets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Masterstudy Elementor Widgets: from n/a through <= 1.2.4. CWE-862Oct 29, 2025 | CVSS5.4v3.1 | EPSS0.164% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-7438HIGH | MasterStudy LMS – Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File UploadThe MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability is difficult to exploit due to timing requirements and environmental f… CWE-434Jul 18, 2025 | CVSS7.5v3.1 | EPSS0.608% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47586CRITICAL | WordPress Motors - Events plugin <= 1.4.7 - Unauthenticated Local File Inclusion vulnerabilityImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events stm-motors-events allows PHP Local File Inclusion.This issue affects Motors - Events: from n/a through <= 1.4.7. CWE-98Jun 6, 2025 | CVSS9.0v3.1 | EPSS0.582% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |