CVE-2025-64214
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64214 is a Missing Authorization (Broken Access Control) vulnerability in the StylemixThemes MasterStudy LMS Pro WordPress plugin that allows unauthenticated attackers to perform arbitrary content deletion. It affects all versions of MasterStudy LMS Pro prior to 4.7.16. The vulnerability was reported by researcher Rafie Muhammad on September 12, 2025, and published by Patchstack on October 12, 2025; it was assigned a CVE identifier and disclosed publicly on December 18, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), corresponding to OWASP Top 10 category A1: Broken Access Control. The plugin fails to properly enforce access controls on certain content management functionality, allowing unauthenticated network-based attackers to invoke privileged operations — specifically, deleting arbitrary content such as posts, pages, or media — without any authentication or user interaction. No authentication or elevated privileges are required, and exploitation requires only low attack complexity over a standard HTTP request (Patchstack).

Impact

Successful exploitation allows an unauthenticated remote attacker to delete arbitrary content from the affected WordPress site, including posts, pages, and media files. This primarily affects the integrity and availability of site content, with a CVSS-assessed high confidentiality impact as well, potentially exposing sensitive data depending on the content targeted. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the MasterStudy LMS Pro plugin (versions < 4.7.16) using tools like WPScan, Shodan, or Google dorks targeting plugin-specific paths (e.g., /wp-content/plugins/masterstudy-lms-learning-management-system-pro/).
  2. Identify vulnerable endpoint: Locate the plugin's content management REST API endpoint or admin-ajax action that lacks proper authorization checks for content deletion operations.
  3. Craft unauthenticated request: Send a crafted HTTP POST or GET request to the vulnerable endpoint without any authentication credentials, supplying the target content ID (post, page, or media item) as a parameter.
  4. Trigger arbitrary deletion: The missing authorization check allows the request to proceed, causing the WordPress site to delete the specified content item as if the request came from an authorized user.
  5. Mass exploitation: Automate the above steps across thousands of sites using scripted scanning and exploitation tools, consistent with the mass-campaign pattern Patchstack associates with this vulnerability class (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to WordPress admin-ajax endpoints or REST API routes associated with the MasterStudy LMS Pro plugin (e.g., paths containing masterstudy-lms-learning-management-system-pro); repeated requests from a single IP targeting content deletion actions.
  • Logs: WordPress access logs showing POST requests to /wp-admin/admin-ajax.php or /wp-json/ endpoints with MasterStudy-specific action parameters from unauthenticated sessions; unexpected 200 responses to deletion-type requests without a logged-in user session.
  • File System / Database: Unexpected disappearance of posts, pages, or media files from the WordPress database (wp_posts table entries with post_status changed to trash or deleted); WordPress activity logs (if enabled via plugins like WP Activity Log) showing content deletions with no associated authenticated user.

Mitigation and workarounds

The vendor has released MasterStudy LMS Pro version 4.7.16, which patches this vulnerability. Site administrators should update the plugin to version 4.7.16 or later immediately. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its subscribers that blocks exploitation attempts until the plugin is updated. If updating is not immediately possible, consider temporarily deactivating the plugin or restricting access to the WordPress site via IP allowlisting (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability through researcher Rafie Muhammad, classifies it as high priority and warns of potential mass-exploitation campaigns targeting WordPress sites. No notable independent researcher commentary, vendor statements beyond the patch release, or significant media coverage has been identified at this time (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15991HIGH8.8
  • file-manager
NoYesAug 06, 2026
CVE-2026-15459HIGH8.1
  • wpmudev-updates
NoYesAug 06, 2026
CVE-2026-7529HIGH7.5
  • wisecampaign
NoYesAug 05, 2026
CVE-2026-18325HIGH7.2
  • forminator
NoYesAug 06, 2026
CVE-2026-16636HIGH7.2
  • fluent-smtp
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management