The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized modification and deletion of data due to a missing capability checks on multiple REST API endpoints in all versions up to, and including, 3.7.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload or delete arbitrary media files, delete or modify posts, and create/manage course templates
We have discovered 1,571 live websites that are affected by CVE-2025-13766.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,571 live websites (96% of Masterstudy LMS Learning Management System install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 113 versions ( 97% of all versions) |
| 407 websites | |
| 123 websites | |
| 116 websites | |
| 79 websites | |
| 74 websites | |
| 72 websites | |
| 65 websites | |
| 63 websites | |
| 51 websites | |
| 27 websites |
| .com | 702 websites |
| .org | 121 websites |
| .it | 56 websites |
| .com.br | 45 websites |
| .net | 42 websites |
| .de | 34 websites |
| .fr | 28 websites |
| .es | 26 websites |
| .co.uk | 23 websites |
| .nl | 22 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.org | **,*** | ||
| *******.org | ***,*** | ||
| **************.***.br | ***,*** | ||
| ***********.**.za | ***,*** | ||
| ***********.***.co | ***,*** | ||
| *****.org | ***,*** | ||
| ************************.com | ***,*** | ||
| *****.**************.com | ***,*** | ||
| ********.*******.***.cl | ***,*** | ||
| ***.***************.eu | ***,*** |
FAQ