
MasterStudy LMS WordPress Plugin – for Online Courses and Education Security & Risk Analysis
wordpress.org/plugins/masterstudy-lms-learning-management-systemLearning Management System and eLearning plugin for WordPress. Create easily LMS WordPress website, add and sell Courses, Lessons, Quizzes online.
Is MasterStudy LMS WordPress Plugin – for Online Courses and Education Safe to Use in 2026?
Mostly Safe
Score 76/100MasterStudy LMS WordPress Plugin – for Online Courses and Education is generally safe to use. 29 past CVEs were resolved.
The MasterStudy LMS plugin exhibits a mixed security posture. While a significant percentage of SQL queries use prepared statements and a good portion of output is properly escaped, several concerning areas require attention. The high number of AJAX handlers without authentication checks (79 out of 110) presents a substantial attack surface. Furthermore, two REST API routes lack permission callbacks. The presence of "unserialize" as a dangerous function, coupled with two high-severity taint analysis flows with unsanitized paths, indicates potential vulnerabilities related to data deserialization and path traversal.
The plugin's historical vulnerability data is a significant concern. With 24 known CVEs, including 5 critical and 3 high-severity issues, and a recent vulnerability recorded in February 2026, there's a pattern of recurring security weaknesses. Common vulnerability types like race conditions, improper privilege management, CSRF, RFI, and SQL injection suggest persistent issues in how the plugin handles user input, authorization, and resource management. While there are currently no unpatched CVEs, the sheer volume and severity of past vulnerabilities suggest a need for rigorous and ongoing security audits and patching processes.
In conclusion, MasterStudy LMS has areas of strength in its code implementation, particularly regarding SQL preparedness and output escaping. However, the large, unprotected attack surface, concerning taint analysis flows, and a history of numerous critical and high-severity vulnerabilities significantly outweigh these positives. The plugin requires immediate attention to address its exposed entry points and to implement more robust authorization and sanitization mechanisms to prevent future exploitation.
Key Concerns
- Large attack surface without auth (AJAX)
- REST API routes without permission callbacks
- Dangerous function 'unserialize' found
- High severity taint flows with unsanitized paths
- History of 5 critical CVEs
- History of 3 high severity CVEs
- Recent vulnerability (2026-02-13)
- Common vulnerability: Race Condition
- Common vulnerability: Improper Privilege Management
- Common vulnerability: CSRF
- Common vulnerability: PHP Remote File Inclusion
- Common vulnerability: Incorrect Privilege Assignment
- Common vulnerability: Missing Authorization
- Common vulnerability: Exposure of Sensitive Information
- Common vulnerability: SQL Injection
- Common vulnerability: Cross-site Scripting
MasterStudy LMS WordPress Plugin – for Online Courses and Education Security Vulnerabilities
CVEs by Year
Severity Breakdown
29 total CVEs
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.30 - Missing Authorization
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.29 - Authenticated (Subscriber+) SQL Injection
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.25 - Authenticated (Subscriber+) SQL Injection
MasterStudy LMS <= 3.7.25 - Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion
MasterStudy LMS <= 3.6.27 - Authenticated (Instructor+) SQL Injection
MasterStudy LMS <= 3.6.20 - Authenticated (Instructor+) Sensitive Information Exposure
MasterStudy LMS <= 3.6.20 - Authenticated (Subscriber+) Race Condition to Multiple Reviews
MasterStudy LMS <= 3.6.20 - Missing Authorization
MasterStudy LMS <= 3.6.15 - Missing Authorization
MasterStudy LMS <= 3.5.28 - Authenticated (Contributor+) Local File Inclusion
MasterStudy LMS <= 3.5.28 - Missing Authorization
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.23 - Unauthenticated Limited Privilege Escalation to Instructor
MasterStudy LMS <= 3.2.12 - Missing Authorization
MasterStudy LMS <= 3.2.1 - Cross-Site Request Forgery
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.3.8 - Missing Authorization
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal
MasterStudy LMS <= 3.2.13 - Missing Authorization to Sensitive Information Exposure in search_posts
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.10 - Basic Information Exposure via REST route
MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection
MasterStudy LMS <= 3.0.17 - Privilege Escalation
MasterStudy LMS <= 3.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
MasterStudy LMS <= 3.0.8 - Missing Authorization to Course Category Creation
MasterStudy LMS WordPress Plugin <= 2.9.34 - Missing Authorization via wp_ajax_stm_wpcfto_get_settings
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
MasterStudy LMS WordPress Plugin – for Online Courses and Education Release Timeline
MasterStudy LMS WordPress Plugin – for Online Courses and Education Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MasterStudy LMS WordPress Plugin – for Online Courses and Education Attack Surface
AJAX Handlers 110
REST API Routes 10
Shortcodes 12
WordPress Hooks 323
Scheduled Events 1
Maintenance & Trust
MasterStudy LMS WordPress Plugin – for Online Courses and Education Maintenance & Trust
Maintenance Signals
Community Trust
MasterStudy LMS WordPress Plugin – for Online Courses and Education Alternatives
Tutor LMS – eLearning and online course solution
tutor
A complete WordPress LMS plugin to create any eLearning website easily.
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am …
Tutor LMS Divi Modules
tutor-lms-divi-modules
Get 26+ Tutor LMS Divi Page builder widgets to create an entire eLearning site and design custom course pages, course carousels, listings, and more.
Dozent LMS – Powerful WordPress LMS plugin
dozent-lms
Powerful and most advanced WordPress LMS plugin for creating your eLearning and online course platform with WordPress.
Lenxel AI LMS – Course Lesson Generator
lenxel-core
Lenxel AI LMS is a WordPress plugin that provides a comprehensive Learning Management System with AI-assisted course creation.
MasterStudy LMS WordPress Plugin – for Online Courses and Education Developer Profile
8 plugins · 56K total installs
How We Detect MasterStudy LMS WordPress Plugin – for Online Courses and Education
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/masterstudy-lms-learning-management-system/assets/css/lms-elementor.css/wp-content/plugins/masterstudy-lms-learning-management-system/assets/js/elementor-widgets/helpers/add-overlay.js/wp-content/plugins/masterstudy-lms-learning-management-system/assets/js/elementor-widgets/helpers/unlock-banner.js/wp-content/plugins/masterstudy-lms-learning-management-system/assets/vendors/swiper-bundle.min.js/wp-content/plugins/masterstudy-lms-learning-management-system/assets/js/elementor-widgets/slider/slider-editor.js/wp-content/plugins/masterstudy-lms-learning-management-system/assets/vendors/select2.min.js/wp-content/plugins/masterstudy-lms-learning-management-system/assets/js/elementor-widgets/courses/courses-editor.js/wp-content/plugins/masterstudy-lms-learning-management-system/assets/js/elementor-widgets/countdown.js+2 moreassets/js/elementor-widgets/helpers/add-overlay.jsassets/js/elementor-widgets/helpers/unlock-banner.jsassets/vendors/swiper-bundle.min.jsassets/js/elementor-widgets/slider/slider-editor.jsassets/vendors/select2.min.jsassets/js/elementor-widgets/courses/courses-editor.js+3 moremasterstudy-lms-learning-management-system/assets/css/lms-elementor.css?ver=masterstudy-lms-learning-management-system/assets/js/elementor-widgets/helpers/add-overlay.js?ver=masterstudy-lms-learning-management-system/assets/js/elementor-widgets/helpers/unlock-banner.js?ver=masterstudy-lms-learning-management-system/assets/vendors/swiper-bundle.min.js?ver=masterstudy-lms-learning-management-system/assets/js/elementor-widgets/slider/slider-editor.js?ver=masterstudy-lms-learning-management-system/assets/vendors/select2.min.js?ver=masterstudy-lms-learning-management-system/assets/js/elementor-widgets/courses/courses-editor.js?ver=masterstudy-lms-learning-management-system/assets/js/elementor-widgets/countdown.js?ver=masterstudy-lms-learning-management-system/assets/vendors/jquery.countdown.js?ver=masterstudy-lms-learning-management-system/assets/vendors/js.countdown.js?ver=HTML / DOM Fingerprints
stm_lms_courses_carouselstm_lms_courses_gridstm_lms_featured_teacherstm_lms_instructors_carouselstm_lms_recent_coursesstm_lms_certificate_checkerstm_lms_course_bundlesstm_lms_google_classroom+42 more<!-- MasterStudy LMS WordPress Plugin --><!-- MasterStudy LMS Pro tested up to: 4.8 -->masterstudy_elementor_course_templatestm_lms_add_overlay_change