CVE-2026-5060: CWE-639 Authorization Bypass Through User-Controlled Key in stylemix MasterStudy LMS WordPress Plugin – for Online Courses and Education
The MasterStudy LMS WordPress Plugin for Online Courses and Education is affected by an insecure direct object reference vulnerability in all versions up to and including 3.7.14. This vulnerability allows authenticated users with Instructor-level access or higher to delete arbitrary attachments belonging to any user by exploiting a lack of ownership validation in the deletion function. The issue arises from the stm_lms_delete_cover() function not verifying the ownership of the file_id parameter before calling wp_delete_attachment().
AI Analysis
Technical Summary
CVE-2026-5060 is an authorization bypass vulnerability (CWE-639) in the MasterStudy LMS WordPress Plugin up to version 3.7.14. The vulnerability is due to the stm_lms_delete_cover() function failing to validate ownership of the file_id parameter before deleting attachments via wp_delete_attachment(). Authenticated attackers with Instructor-level privileges or higher can exploit this flaw to delete arbitrary attachments by enumerating sequential attachment IDs, potentially impacting data integrity.
Potential Impact
An attacker with Instructor-level or higher privileges can delete attachments belonging to other users, leading to unauthorized modification of content. This can disrupt course materials or user data but does not directly impact confidentiality or availability. The CVSS score is 6.5 (medium severity) reflecting the integrity impact without confidentiality or availability loss.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict Instructor-level access to trusted users only. Monitor for plugin updates from stylemix addressing this vulnerability and apply official patches once released.
CVE-2026-5060: CWE-639 Authorization Bypass Through User-Controlled Key in stylemix MasterStudy LMS WordPress Plugin – for Online Courses and Education
Description
The MasterStudy LMS WordPress Plugin for Online Courses and Education is affected by an insecure direct object reference vulnerability in all versions up to and including 3.7.14. This vulnerability allows authenticated users with Instructor-level access or higher to delete arbitrary attachments belonging to any user by exploiting a lack of ownership validation in the deletion function. The issue arises from the stm_lms_delete_cover() function not verifying the ownership of the file_id parameter before calling wp_delete_attachment().
CVSS v3.1
Score 6.5medium
Affected software
stylemix
MasterStudy LMS WordPress Plugin – for Online Courses and Education
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-5060 is an authorization bypass vulnerability (CWE-639) in the MasterStudy LMS WordPress Plugin up to version 3.7.14. The vulnerability is due to the stm_lms_delete_cover() function failing to validate ownership of the file_id parameter before deleting attachments via wp_delete_attachment(). Authenticated attackers with Instructor-level privileges or higher can exploit this flaw to delete arbitrary attachments by enumerating sequential attachment IDs, potentially impacting data integrity.
Potential Impact
An attacker with Instructor-level or higher privileges can delete attachments belonging to other users, leading to unauthorized modification of content. This can disrupt course materials or user data but does not directly impact confidentiality or availability. The CVSS score is 6.5 (medium severity) reflecting the integrity impact without confidentiality or availability loss.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict Instructor-level access to trusted users only. Monitor for plugin updates from stylemix addressing this vulnerability and apply official patches once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-03-27T18:10:20.617Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a69d4879c2644c7f856ba88
Added to database: 07/29/2026, 10:23:03 UTC
Last enriched: 08/05/2026, 14:55:23 UTC
Last updated: 09/12/2026, 10:01:32 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.