Sceawere
Vulnerability Detail
CVE-2026-105079UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MasterStudy LMS Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 4h ago
- Vendor
- StylemixThemes
- Product
- MasterStudy LMS
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes MasterStudy LMS masterstudy-lms-learning-management-system allows Stored XSS.This issue affects MasterStudy LMS: from n/a through 3.7.52.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T13:17:13.050Z",
"pubdate": "2026-10-08T13:17:13.050Z",
"executiveSummary": "The MasterStudy LMS plugin for WordPress is vulnerable to a Stored Cross-Site Scripting (XSS) flaw, categorized under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThis vulnerability allows an attacker to inject arbitrary malicious JavaScript into the application, which is then persisted in the database.\nThe vulnerability affects MasterStudy LMS versions up to and including 3.7.52.\nSuccessful exploitation permits unauthorized script execution within the context of an authenticated user's browser session.\nImpact includes potential session hijacking, unauthorized actions performed on behalf of legitimate users, and the compromise of sensitive administrative or user data.\nThe attack is mitigated by the need for the injected script to be rendered in the browser of a target victim, typically an administrator or instructor accessing the vulnerable component, indicating a requirement for user interaction or privilege-based context.",
"technicalDetails": "The vulnerability originates from the insufficient sanitization and validation of user-supplied input before it is processed and stored within the MasterStudy LMS database.\nSpecifically, the application fails to properly neutralize executable code or scripts within specific input fields or data submission modules provided by the plugin.\nBecause the input is stored server-side without adequate output encoding, the payload is rendered directly into the Document Object Model (DOM) of the affected web pages whenever a user with appropriate permissions accesses the compromised data entry.\nThe attack flow begins when an attacker identifies an input vector within the MasterStudy LMS interface that persists data. By submitting a crafted payload—such as <script>alert(document.cookie)</script>—the attacker forces the application to store the script within the database.\nUpon subsequent retrieval by the application, the server serves the stored malicious script as part of the HTML response. When an administrator or another user views the impacted page, the browser interprets the script as legitimate content from the origin, thereby executing the payload in the victim's security context.\nThe vulnerability is present in versions up to 3.7.52. Exploitation does not require external network access if the attacker has already gained access to the platform's input vectors, though it is limited by the specific privilege requirements of the vulnerable plugin feature.\nThe lack of context-aware output encoding ensures that the injected script bypasses browser-side security filters, allowing for the exfiltration of session cookies, modification of the DOM to perform unauthorized administrative operations, or the redirection of users to malicious third-party domains.\nBecause the payload is persisted, the XSS remains active until the specific entry is manually purged from the database or the vulnerable code path is patched."
}