Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
MasterStudy LMS
Stylemix
Developer
3.7.2
Latest version
10,000
Installations
4 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
1 present
24 fixed
15 Mitigation rules
SQL Injection vulnerability
<= 3.6.27
3 days ago
Sensitive Data Exposure vulnerability
<= 3.6.20
Oct 16, 2025
Broken Access Control Vulnerability
<= 3.6.20
Sep 22, 2025
Race Condition Vulnerability
<= 3.6.20
Sep 22, 2025
Broken Access Control Vulnerability
<= 3.6.15
Sep 3, 2025
Broken Access Control vulnerability
<= 3.5.28
Apr 4, 2025
Local File Inclusion vulnerability
<= 3.5.28
Apr 4, 2025
Privilege Escalation to Instructor vulnerability
< 3.3.24
Jul 22, 2024
Broken Access Control vulnerability
<= 3.2.12
Jun 20, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 3.2.1
Jun 20, 2024
Missing Authorization vulnerability
<= 3.3.8
Apr 30, 2024
Unauthenticated Local File Inclusion via template vulnerability
<= 3.3.3
Apr 5, 2024
Unauthenticated Privilege Escalation via stm_lms_register AJAX Action vulnerability
<= 3.3.1
Apr 1, 2024
Unauthenticated Local File Inclusion via modal vulnerability
<= 3.3.0
Apr 1, 2024
Missing Authorization to Sensitive Information Exposure in search_posts vulnerability
<= 3.2.13
Mar 18, 2024
Basic Information Exposure via REST route vulnerability
<= 3.2.10
Mar 7, 2024
Unauthenticated SQL Injection vulnerability
<= 3.2.5
Feb 19, 2024
Unauthenticated Instructor Account Creation vulnerability
< 3.0.18
Sep 12, 2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 2.7.9
Jul 19, 2023
Cross Site Scripting (XSS) vulnerability
<= 3.0.8
Jun 15, 2023
Broken Access Control vulnerability
<= 3.0.8
Jun 15, 2023
Missing Authorization via wp_ajax_stm_wpcfto_get_settings vulnerability
<= 2.9.34
Apr 4, 2023
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
< 2.8.0
Feb 28, 2022
Sensitive Information Disclosure vulnerability
< 2.8.0
Feb 28, 2022
Unauthenticated Admin Account Creation vulnerability
<= 2.7.5
Feb 1, 2022