Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jul 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stylemix
Stylemix masterstudy Lms Wordpress Plugin – For Online Courses And Education Wordpress Wordpress wordpress |
|
| Vendors & Products |
Stylemix
Stylemix masterstudy Lms Wordpress Plugin – For Online Courses And Education Wordpress Wordpress wordpress |
Wed, 29 Jul 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary attachments belonging to any user by enumerating sequential attachment IDs. | |
| Title | MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-07-29T15:07:22.056Z
Reserved: 2026-03-27T18:10:20.617Z
Link: CVE-2026-5060
Updated: 2026-07-29T15:07:18.204Z
Status : Deferred
Published: 2026-07-29T11:16:50.093
Modified: 2026-07-30T14:01:30.413
Link: CVE-2026-5060
No data.
OpenCVE Enrichment
Updated: 2026-08-03T13:45:03Z