Missing Authorization Vulnerability in Stylemix MasterStudy LMS Software
CVE-2025-54744

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-54744?

The vulnerability in MasterStudy LMS enables unauthorized access due to incorrectly configured access control security levels. This flaw allows attackers to exploit the system's oversight, potentially gaining access to restricted functionalities, which could compromise sensitive data integrity and application security. Users of versions starting from n/a up to 3.6.15 are recommended to review their access control configurations and apply necessary corrections to mitigate the risk.

Affected Version(s)

MasterStudy LMS <= 3.6.15

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 (Patchstack Alliance)
.
CVE-2025-54744 : Missing Authorization Vulnerability in Stylemix MasterStudy LMS Software