Stylemixthemes

First CVE: Feb 24, 2020Active for: 6 yearsTotal CVEs: 64
50.3
VTI Score
TOP TARGET

Stylemixthemes develops a portfolio of WordPress plugins and themes focused on real-estate, education, and business listing applications, including products such as uListing, MasterStudy LMS, and Motors. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes across a relatively concentrated product line that serves many small-to-medium business deployments. The recurring weakness classes—missing authorization, cross-site request forgery, SQL injection, and cross-site scripting—are characteristic of web-application and plugin-layer flaws where insufficient input validation and access controls expose administrative and user-facing functionality. A moderate share of the vendor's disclosures acquire public exploit code, reflecting the accessible nature of WordPress plugin vulnerabilities and the value of automation in targeting these plugins at scale. Defenders should prioritize patching this vendor's releases across their WordPress installations and restrict plugin administrative access; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
64
Total CVEs
More Total CVEs than 99% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Stylemixthemes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2020
6 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (64 CVEs).

64 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin
Mar 7, 20229.892NOYES
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms
Feb 17, 20249.881NOYES
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects
Aug 29, 20249.843NOYES
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for
Apr 9, 20249.840NOYES
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructo
Sep 11, 20237.534NOYES
The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for una
Mar 29, 20249.832NONO
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options c
Feb 24, 20206.531NOYES
The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the
Mar 29, 20249.830NONO
Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.
Sep 27, 20219.830NONO
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.
Sep 27, 20219.829NONO

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products64 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network64 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low64 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None48 (75.0%)
Unknown0 (0.0%)
Required16 (25.0%)
Privileges Required
Low20 (31.3%)
High4 (6.3%)
None40 (62.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (64 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.6% of CVEs· 97th percentile
Nuclei
5 CVEs
7.8% of CVEs· 96th percentile
ExploitDB
2 CVEs
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Stylemixthemes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Stylemixthemes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Stylemixthemes's Products

Top CWEs