Vulnerability record · CVE-2024-1512 · published 17 February 2024
CVE-2024-1512: MasterStudy LMS WordPress plugin unauthenticated SQL injection
Stylemixthemes · Masterstudy Lms
The MasterStudy LMS plugin for WordPress is vulnerable to union-based SQL injection through the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to and including 3.2.5. The parameter is not properly escaped and the SQL query is not sufficiently prepared, letting attackers append their own SQL to existing queries. Because the route is reachable without authentication, any exposed site running an affected version is at risk.
Description
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with a 9.8 CVSS score and very high EPSS probability makes this an urgent patch target.
What it is
The MasterStudy LMS plugin for WordPress is vulnerable to union-based SQL injection through the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to and including 3.2.5. The parameter is not properly escaped and the SQL query is not sufficiently prepared, letting attackers append their own SQL to existing queries. Because the route is reachable without authentication, any exposed site running an affected version is at risk.
Impact
An unauthenticated attacker can read sensitive data from the WordPress database, including user credentials and other stored content, and the CVSS vector also rates integrity and availability impact as high.
Attack surface
Reached over the network via the REST route /lms/stm-lms/order/items, specifically the 'user' parameter. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high (0.776, 99.5th percentile), indicating elevated likelihood of exploitation. References are limited to a product changeset and a Wordfence advisory, with no public exploit tag.
What to do
- Update MasterStudy LMS to a version newer than 3.2.5; the fix is in the referenced changeset for StmStatistics.php.
- If immediate patching is not possible, disable or restrict access to the /lms/stm-lms/order/items REST route.
- Deploy a WAF rule blocking union-based SQL injection patterns against the 'user' parameter on that route.
- Audit the WordPress database and user accounts for signs of unauthorized data access after exposure.
- Remove or deactivate the plugin if it is not actively needed.
Detection
- Monitor web server and WAF logs for requests to /lms/stm-lms/order/items containing SQL keywords such as UNION, SELECT or comment sequences in the 'user' parameter.
- Alert on unusual database query errors or unexpected result patterns originating from the LMS REST endpoints.
- Review outbound or database access anomalies and new administrative accounts that could follow data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-1512 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-1512), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.