
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64214 is a Missing Authorization (Broken Access Control) vulnerability in the StylemixThemes MasterStudy LMS Pro WordPress plugin that allows unauthenticated attackers to perform arbitrary content deletion. It affects all versions of MasterStudy LMS Pro prior to 4.7.16. The vulnerability was reported by researcher Rafie Muhammad on September 12, 2025, and published by Patchstack on October 12, 2025; it was assigned a CVE identifier and disclosed publicly on December 18, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), corresponding to OWASP Top 10 category A1: Broken Access Control. The plugin fails to properly enforce access controls on certain content management functionality, allowing unauthenticated network-based attackers to invoke privileged operations — specifically, deleting arbitrary content such as posts, pages, or media — without any authentication or user interaction. No authentication or elevated privileges are required, and exploitation requires only low attack complexity over a standard HTTP request (Patchstack).
Successful exploitation allows an unauthenticated remote attacker to delete arbitrary content from the affected WordPress site, including posts, pages, and media files. This primarily affects the integrity and availability of site content, with a CVSS-assessed high confidentiality impact as well, potentially exposing sensitive data depending on the content targeted. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or traffic (Patchstack).
/wp-content/plugins/masterstudy-lms-learning-management-system-pro/).masterstudy-lms-learning-management-system-pro); repeated requests from a single IP targeting content deletion actions./wp-admin/admin-ajax.php or /wp-json/ endpoints with MasterStudy-specific action parameters from unauthenticated sessions; unexpected 200 responses to deletion-type requests without a logged-in user session.wp_posts table entries with post_status changed to trash or deleted); WordPress activity logs (if enabled via plugins like WP Activity Log) showing content deletions with no associated authenticated user.The vendor has released MasterStudy LMS Pro version 4.7.16, which patches this vulnerability. Site administrators should update the plugin to version 4.7.16 or later immediately. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for its subscribers that blocks exploitation attempts until the plugin is updated. If updating is not immediately possible, consider temporarily deactivating the plugin or restricting access to the WordPress site via IP allowlisting (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher Rafie Muhammad, classifies it as high priority and warns of potential mass-exploitation campaigns targeting WordPress sites. No notable independent researcher commentary, vendor statements beyond the patch release, or significant media coverage has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."