stylemixthemes CVE Vulnerabilities & Metrics

Focus on stylemixthemes vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About stylemixthemes Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with stylemixthemes. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total stylemixthemes CVEs: 47
Earliest CVE date: 24 Feb 2020, 19:15 UTC
Latest CVE date: 02 Jan 2025, 12:15 UTC

Latest CVE reference: CVE-2024-37093

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 16

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -20.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -20.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical stylemixthemes CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.25

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 38
4.0-6.9 6
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS stylemixthemes CVEs

These are the five CVEs with the highest CVSS scores for stylemixthemes, sorted by severity first and recency.

All CVEs for stylemixthemes

CVE-2024-37093 stylemixthemes vulnerability CVSS: 0 02 Jan 2025, 12:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes MasterStudy LMS allows Cross Site Request Forgery.This issue affects MasterStudy LMS: from n/a through 3.2.1.

CVE-2024-37094 stylemixthemes vulnerability CVSS: 0 01 Nov 2024, 14:15 UTC

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.

CVE-2024-8379 stylemixthemes vulnerability CVSS: 0 30 Sep 2024, 06:15 UTC

The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Admin.

CVE-2024-6010 stylemixthemes vulnerability CVSS: 0 07 Sep 2024, 12:15 UTC

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.2.1. This is due to the plugin allowing the price field to be manipulated prior to processing via the 'create_cc_order' function, called from the Cost Calculator Builder plugin. This makes it possible for unauthenticated attackers to manipulate the price of orders submitted via the calculator. Note: this vulnerability was partially patched with the release of Cost Calculator Builder version 3.2.17.

CVE-2024-43144 stylemixthemes vulnerability CVSS: 0 29 Aug 2024, 15:15 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

CVE-2024-5973 stylemixthemes vulnerability CVSS: 0 22 Jul 2024, 06:15 UTC

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor accounts, which could be used to get access to functionalities they shouldn't have.

CVE-2024-6012 stylemixthemes vulnerability CVSS: 0 02 Jul 2024, 10:15 UTC

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' functions in all versions up to, and including, 3.2.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary posts and append arbitrary content to existing posts.

CVE-2024-6011 stylemixthemes vulnerability CVSS: 0 02 Jul 2024, 10:15 UTC

The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-5545 stylemixthemes vulnerability CVSS: 0 02 Jul 2024, 08:15 UTC

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary posts and pages.

CVE-2024-35677 stylemixthemes vulnerability CVSS: 0 10 Jun 2024, 16:15 UTC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusion.This issue affects MegaMenu: from n/a through 2.3.12.

CVE-2024-3942 stylemixthemes vulnerability CVSS: 0 02 May 2024, 17:15 UTC

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.3.8. This makes it possible for authenticated attackers, with subscriber level permissions and above, to read and modify content such as course questions, post titles, and taxonomies.

CVE-2024-3136 stylemixthemes vulnerability CVSS: 0 09 Apr 2024, 19:15 UTC

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-1904 stylemixthemes vulnerability CVSS: 0 09 Apr 2024, 19:15 UTC

The MasterStudy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the search_posts function in all versions up to, and including, 3.2.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose draft post titles and excerpts.

CVE-2024-2411 stylemixthemes vulnerability CVSS: 0 29 Mar 2024, 09:15 UTC

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVE-2024-2409 stylemixthemes vulnerability CVSS: 0 29 Mar 2024, 09:15 UTC

The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes it possible for unauthenticated attackers to register a user with administrator-level privileges when MasterStudy LMS Pro is installed and the LMS Forms Editor add-on is enabled.

CVE-2024-2106 stylemixthemes vulnerability CVSS: 0 13 Mar 2024, 16:15 UTC

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 3.2.10. This can allow unauthenticated attackers to extract sensitive data including all registered user's username and email addresses which can be used to help perform future attacks.

CVE-2024-1512 stylemixthemes vulnerability CVSS: 0 17 Feb 2024, 08:15 UTC

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2023-50852 stylemixthemes vulnerability CVSS: 0 28 Dec 2023, 12:15 UTC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Booking Calendar | Appointment Booking | BookIt.This issue affects Booking Calendar | Appointment Booking | BookIt: from n/a through 2.4.3.

CVE-2023-46207 stylemixthemes vulnerability CVSS: 0 13 Nov 2023, 03:15 UTC

Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.

CVE-2023-46208 stylemixthemes vulnerability CVSS: 0 27 Oct 2023, 21:15 UTC

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.

CVE-2023-4278 stylemixthemes vulnerability CVSS: 0 11 Sep 2023, 20:15 UTC

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instructor. They can then add courses and/or posts.

CVE-2023-2834 stylemixthemes vulnerability CVSS: 0 30 Jun 2023, 02:15 UTC

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVE-2023-35093 stylemixthemes vulnerability CVSS: 0 22 Jun 2023, 12:15 UTC

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.8 versions allows any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order like email, username, and more.

CVE-2023-35090 stylemixthemes vulnerability CVSS: 0 22 Jun 2023, 11:15 UTC

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin <= 3.0.7 versions.

CVE-2021-4381 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database.

CVE-2021-4370 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct numerous administrative actions, including those less critical than the explicitly outlined ones in our detection.

CVE-2021-4357 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and pages.

CVE-2021-4346 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing the admin account's email address.

CVE-2021-4345 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities.

CVE-2021-4343 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create accounts, even those with administrator privileges.

CVE-2021-4341 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any WordPress option in the database.

CVE-2021-4340 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2021-4339 stylemixthemes vulnerability CVSS: 0 07 Jun 2023, 02:15 UTC

The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all users and their email address in the database.

CVE-2022-45815 stylemixthemes vulnerability CVSS: 0 25 May 2023, 11:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes GDPR Compliance & Cookie Consent plugin <= 1.2 versions.

CVE-2022-38716 stylemixthemes vulnerability CVSS: 0 25 May 2023, 11:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.

CVE-2022-38356 stylemixthemes vulnerability CVSS: 0 25 May 2023, 11:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes WordPress Header Builder Plugin – Pearl plugin <= 1.3.4 versions.

CVE-2022-3989 stylemixthemes vulnerability CVSS: 0 12 Dec 2022, 18:15 UTC

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

CVE-2022-0441 stylemixthemes vulnerability CVSS: 7.5 07 Mar 2022, 09:15 UTC

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

CVE-2021-36880 stylemixthemes vulnerability CVSS: 7.5 27 Sep 2021, 16:15 UTC

Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.

CVE-2021-36879 stylemixthemes vulnerability CVSS: 7.5 27 Sep 2021, 16:15 UTC

Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.

CVE-2021-36877 stylemixthemes vulnerability CVSS: 4.3 27 Sep 2021, 16:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to modify user roles.

CVE-2021-36876 stylemixthemes vulnerability CVSS: 6.8 27 Sep 2021, 16:15 UTC

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in WordPress uListing plugin (versions <= 2.0.5) as it lacks CSRF checks on plugin administration pages.

CVE-2021-36875 stylemixthemes vulnerability CVSS: 3.5 27 Sep 2021, 16:15 UTC

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability in WordPress uListing plugin (versions <= 2.0.5). Vulnerable parameters: &filter[id], &filter[user], &filter[expired_date], &filter[created_date], &filter[updated_date].

CVE-2021-36874 stylemixthemes vulnerability CVSS: 6.5 27 Sep 2021, 16:15 UTC

Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).

CVE-2021-36878 stylemixthemes vulnerability CVSS: 4.3 27 Sep 2021, 15:15 UTC

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

CVE-2019-17229 stylemixthemes vulnerability CVSS: 4.3 24 Feb 2020, 19:15 UTC

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.

CVE-2019-17228 stylemixthemes vulnerability CVSS: 6.4 24 Feb 2020, 19:15 UTC

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.