Missing Authorization Vulnerability in MasterStudy LMS by Stylemix
CVE-2025-59576

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-59576?

The Stylemix MasterStudy LMS suffers from a missing authorization vulnerability, which allows attackers to exploit incorrectly configured access control security levels. This can lead to unauthorized users gaining access to restricted functionalities. The issue affects versions of MasterStudy LMS up to 3.6.20, potentially exposing sensitive data and enabling malicious actions on behalf of users without proper permissions. Website administrators are urged to upgrade to the latest version to mitigate this risk.

Affected Version(s)

MasterStudy LMS <= 3.6.20

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bibek Dhakal (Patchstack Alliance)
.
CVE-2025-59576 : Missing Authorization Vulnerability in MasterStudy LMS by Stylemix