Missing Authorization in StylemixThemes MasterStudy LMS Pro
CVE-2025-64214

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 December 2025

What is CVE-2025-64214?

A missing authorization vulnerability exists in StylemixThemes MasterStudy LMS Pro, which allows unauthorized users to access functionalities not properly constrained by Access Control Lists (ACLs). This issue affects all versions prior to 4.7.16, potentially leading to unintended operations and data exposure. Users of this plugin need to review and update their systems to ensure proper authorization controls are in place to safeguard their applications.

Affected Version(s)

MasterStudy LMS Pro 0 <= 4.7.16

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.