← Vulnerability feed

Vulnerability record · CVE-2024-1512 · published 17 February 2024

CVE-2024-1512: MasterStudy LMS WordPress plugin unauthenticated SQL injection

Stylemixthemes · Masterstudy Lms

The MasterStudy LMS plugin for WordPress is vulnerable to union-based SQL injection through the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to and including 3.2.5. The parameter is not properly escaped and the SQL query is not sufficiently prepared, letting attackers append their own SQL to existing queries. Because the route is reachable without authentication, any exposed site running an affected version is at risk.

9.8 CVSS 3.1 Critical EPSS 78% · top 0.5% CWE-89 · SQL injection
9.8CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with a 9.8 CVSS score and very high EPSS probability makes this an urgent patch target.

What it is

The MasterStudy LMS plugin for WordPress is vulnerable to union-based SQL injection through the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to and including 3.2.5. The parameter is not properly escaped and the SQL query is not sufficiently prepared, letting attackers append their own SQL to existing queries. Because the route is reachable without authentication, any exposed site running an affected version is at risk.

Impact

An unauthenticated attacker can read sensitive data from the WordPress database, including user credentials and other stored content, and the CVSS vector also rates integrity and availability impact as high.

Attack surface

Reached over the network via the REST route /lms/stm-lms/order/items, specifically the 'user' parameter. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no ransomware use documented, but EPSS is very high (0.776, 99.5th percentile), indicating elevated likelihood of exploitation. References are limited to a product changeset and a Wordfence advisory, with no public exploit tag.

What to do

  • Update MasterStudy LMS to a version newer than 3.2.5; the fix is in the referenced changeset for StmStatistics.php.
  • If immediate patching is not possible, disable or restrict access to the /lms/stm-lms/order/items REST route.
  • Deploy a WAF rule blocking union-based SQL injection patterns against the 'user' parameter on that route.
  • Audit the WordPress database and user accounts for signs of unauthorized data access after exposure.
  • Remove or deactivate the plugin if it is not actively needed.

Detection

  • Monitor web server and WAF logs for requests to /lms/stm-lms/order/items containing SQL keywords such as UNION, SELECT or comment sequences in the 'user' parameter.
  • Alert on unusual database query errors or unexpected result patterns originating from the LMS REST endpoints.
  • Review outbound or database access anomalies and new administrative accounts that could follow data exfiltration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-1512 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-37094Stylemixthemes masterstudy lms missing authorization vulnerabilityMissing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This i…EPSS 0.41%9.8CVE-2024-3136Stylemixthemes masterstudy lms php remote file inclusion vulnerabilityThe MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' paramet…EPSS 5.0%9.8CVE-2024-2409Stylemixthemes masterstudy lms vulnerabilityThe MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficie…EPSS 0.83%9.8CVE-2024-2411Stylemixthemes masterstudy lms php remote file inclusion vulnerabilityThe MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter.…EPSS 1.5%9.8CVE-2022-0441MasterStudy LMS WordPress plugin privilege escalation via registrationThe MasterStudy LMS WordPress plugin before 2.7.6 fails to validate some parameters supplied during new account registration, letting an unauthentica…EPSS 85%analysed8.8CVE-2024-37093Stylemixthemes masterstudy lms cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forg…EPSS 0.21%8.8CVE-2024-5973Stylemixthemes masterstudy lms vulnerabilityThe MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used …EPSS 0.49%7.5CVE-2024-2106Stylemixthemes masterstudy lms information exposure vulnerabilityThe MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to,…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2024-1512), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.