WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in MasterStudy LMS WordPress Plugin – for Online Courses and Education

Learning Management System and eLearning plugin for WordPress. Create easily LMS WordPress website, add and sell Courses, Lessons, Quizzes online.

32Reported vulnerabilities
9.8Highest CVSS score
3.7.42Latest version
10,000+Active installs

What to do now

Update MasterStudy LMS WordPress Plugin – for Online Courses and Education to 3.7.42 or later. 32 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 14, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-1512 Critical 9.8 77.7% 3.2.5 and earlier 3.2.6 February 17, 2024
CVE-2024-3136 Critical 9.8 5.0% Before 3.3.4 3.3.4 April 9, 2024
CVE-2024-2411 Critical 9.8 1.5% Before 3.3.1 3.3.1 March 29, 2024
CVE-2024-2409 Critical 9.8 0.8% Before 3.3.2 3.3.2 March 29, 2024
CVE-2025-32141 High 8.8 0.7% 3.5.28 and earlier 3.5.29 April 4, 2025
CVE-2024-2106 High 7.5 0.8% Before 3.2.11 3.2.11 March 13, 2024
CVE-2026-81342 High 7.2 0.2% Before 3.7.43 3.7.43 August 27, 2026
CVE-2023-35093 Medium 6.5 0.6% 3.0.8 and earlier 3.0.9 June 22, 2023
CVE-2026-5060 Medium 6.5 0.2% 0 to 3.7.23 (inclusive) 3.7.24 July 29, 2026
CVE-2026-42730 Medium 6.5 0.3% 3.7.29 and earlier 3.7.30 May 24, 2026
CVE-2026-40766 Medium 6.5 0.3% 3.7.25 and earlier 3.7.26 April 21, 2026
CVE-2026-4817 Medium 6.5 0.5% 0 to 3.7.25 (inclusive) 3.7.26 April 17, 2026
CVE-2025-64366 Medium 6.5 0.3% 3.6.27 and earlier 3.6.28 October 23, 2025
CVE-2026-68568 Medium 6.3 0.2% 3.7.41 and earlier 3.7.42 August 18, 2026
CVE-2026-57330 Medium 6.4 0.2% 3.7.27 and earlier 3.7.28 June 29, 2026
CVE-2026-0559 Medium 6.4 0.2% 0 to 3.7.11 (inclusive) 3.7.12 February 14, 2026
CVE-2023-35090 Medium 5.4 0.4% 3.0.7 and earlier 3.0.9 June 22, 2023
CVE-2026-81026 Medium 5.3 0.1% Before 3.7.40 3.7.40 August 27, 2026
CVE-2026-28145 Medium 5.3 0.1% 3.7.39 and earlier 3.7.40 July 31, 2026
CVE-2025-13766 Medium 5.4 0.2% 3.7.6 and earlier 3.7.7 January 5, 2026
CVE-2024-37094 Medium 5.3 0.4% 3.2.12 and earlier 3.2.13 June 20, 2024
CVE-2026-81200 Medium 4.3 0.2% Before 3.7.42 3.7.42 August 29, 2026
CVE-2026-73404 Medium 4.3 0.3% 3.7.41 and earlier 3.7.42 August 18, 2026
CVE-2026-57640 Medium 4.3 0.3% 3.7.30 and earlier 3.7.31 June 26, 2026
CVE-2025-59575 Medium 4.3 0.3% 3.6.20 and earlier 3.6.21 October 16, 2025
CVE-2025-59577 Medium 4.3 0.2% 3.6.20 and earlier 3.6.21 September 22, 2025
CVE-2025-59576 Medium 4.3 0.2% 3.6.20 and earlier 3.6.21 September 22, 2025
CVE-2025-54744 Medium 4.3 0.2% 3.6.15 and earlier 3.6.16 September 3, 2025
CVE-2025-32237 Medium 4.3 0.4% 3.5.28 and earlier 3.5.29 April 4, 2025
CVE-2024-37093 Medium 4.3 0.2% 3.2.1 and earlier 3.2.2 June 20, 2024
CVE-2024-1904 Medium 4.3 0.5% Before 3.3.0 3.3.0 April 9, 2024
WF-1ddcd2eb-fd7a-48b7-b9ea-3632d49e9734 Medium 4.3 2.9.34 and earlier 2.9.35 April 3, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.