Stylemixthemes
Stylemixthemes develops a portfolio of WordPress plugins and themes focused on real-estate, education, and business listing applications, including products such as uListing, MasterStudy LMS, and Motors. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes across a relatively concentrated product line that serves many small-to-medium business deployments. The recurring weakness classes—missing authorization, cross-site request forgery, SQL injection, and cross-site scripting—are characteristic of web-application and plugin-layer flaws where insufficient input validation and access controls expose administrative and user-facing functionality. A moderate share of the vendor's disclosures acquire public exploit code, reflecting the accessible nature of WordPress plugin vulnerabilities and the value of automation in targeting these plugins at scale. Defenders should prioritize patching this vendor's releases across their WordPress installations and restrict plugin administrative access; current exploitation activity and exposure counts are shown alongside this summary.
Trends Over Time
The number and severity of CVEs published that impact products developed by Stylemixthemes over time
Products(11 total)
Top CVEs
Signals from CVEs in this vendor scope (64 CVEs).
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0441CRITICAL The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin | Mar 7, 2022 | 9.8 | 92 | NO | YES |
CVE-2024-1512CRITICAL The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms | Feb 17, 2024 | 9.8 | 81 | NO | YES |
CVE-2024-43144CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects | Aug 29, 2024 | 9.8 | 43 | NO | YES |
CVE-2024-3136CRITICAL The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for | Apr 9, 2024 | 9.8 | 40 | NO | YES |
CVE-2023-4278HIGH The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructo | Sep 11, 2023 | 7.5 | 34 | NO | YES |
CVE-2024-2411CRITICAL The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for una | Mar 29, 2024 | 9.8 | 32 | NO | NO |
CVE-2019-17228MEDIUM includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options c | Feb 24, 2020 | 6.5 | 31 | NO | YES |
CVE-2024-2409CRITICAL The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the | Mar 29, 2024 | 9.8 | 30 | NO | NO |
CVE-2021-36879CRITICAL Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration. | Sep 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-36880CRITICAL Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom. | Sep 27, 2021 | 9.8 | 29 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this vendor scope (64 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID that affects a product developed by Stylemixthemes.
Media Mentions
Media articles that mention a CVE ID that affects a product developed by Stylemixthemes — matched by CVE ID, not by vendor name.