CVE-2025-64215: Missing Authorization in MasterStudy LMS Pro 4.7.15 and Earlier
StylemixThemes MasterStudy LMS Pro contains a missing authorization vulnerability that allows unauthenticated attackers to access functionality that should be restricted by access control lists (ACLs). An attacker can exploit this flaw to perform unauthorized actions affecting the integrity and availability of the learning management system without requiring authentication or user interaction.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Weaknesses (CWE)
- CWE-862
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2025-64215 is a CWE-862 (Missing Authorization) vulnerability in MasterStudy LMS Pro versions before 4.7.16. The application fails to properly enforce access controls on certain functions, permitting unauthenticated network requests to execute restricted operations. The CVSS 3.1 score of 6.5 (MEDIUM) reflects the network-exploitable nature with low complexity, no privileges required, but limited scope of impact (no confidentiality loss, minor integrity and availability compromise).
Business impact
Organizations deploying MasterStudy LMS Pro risk unauthorized modification of course content, student records, or system settings without detection. While confidentiality remains protected, an attacker could deface course materials, corrupt enrollment data, or disrupt service availability, undermining institutional trust in the platform and potentially violating data stewardship obligations to students and staff.
Affected systems
MasterStudy LMS Pro versions prior to 4.7.16 are vulnerable. Organizations should inventory all deployments of this plugin, including production, staging, and development environments. The vulnerability affects any installation that has not applied the patched version or implemented compensating controls.
Exploitability
This vulnerability is network-exploitable without authentication or special privileges, making it relatively straightforward to trigger. No user interaction is required. However, exploitation requires knowledge of the specific unprotected endpoints or functionality, reducing opportunistic attack likelihood. The absence of public exploit code and lack of KEV status suggest active exploitation has not yet been widely observed.
Remediation
Upgrade MasterStudy LMS Pro to version 4.7.16 or later immediately. After patching, verify ACL enforcement across all administrative and protected endpoints. Review access logs for the 30 days preceding the patch date to identify any suspicious unauthorized requests or data modifications.
Patch guidance
Apply the MasterStudy LMS Pro update to version 4.7.16 as released by StylemixThemes. Verify the update against the vendor advisory to confirm patch completeness. Test the patch in a non-production environment before broad deployment to ensure no functional regression with existing integrations or customizations. Coordinate deployment timing with course calendars to minimize disruption.
Detection guidance
Monitor access logs for unauthenticated requests to administrative endpoints, API routes, or functions typically requiring login. Look for patterns of repeated access attempts to restricted functionality. Enable detailed audit logging in MasterStudy LMS Pro to capture authorization failures and unauthorized action attempts. Web application firewalls should be configured to enforce authentication requirements on protected resources.
Why prioritize this
Although rated MEDIUM severity, this vulnerability should be prioritized within 30 days because it requires no authentication, network exploitability, and ability to alter data integrity. LMS platforms hold sensitive educational and personal data; unauthorized modification poses reputational and compliance risk. The absence of KEV status does not indicate low threat—it reflects lack of current widespread exploitation, not patch maturity.
Risk score, explained
The CVSS 3.1 score of 6.5 reflects a network-accessible vulnerability with low attack complexity and no privilege or interaction requirements (high exploitability), offset by the lack of confidentiality impact and limited scope of integrity and availability effects. Organizations handling sensitive student data may assess local risk higher based on data sensitivity and exposure of the LMS to untrusted networks.
Frequently asked questions
What is the difference between Missing Authorization and Missing Authentication?
Authentication verifies who you are; authorization verifies what you're allowed to do. This CVE is about authorization—an attacker can reach protected functions without proving their identity (missing auth checks), not necessarily by bypassing login alone. The vulnerability allows accessing restricted functionality without proper ACL enforcement.
Should we patch immediately or can we wait?
Patch within 30 days if possible. The attack surface is network-wide and requires no credentials, making opportunistic exploitation plausible once word spreads. Verify your version against 4.7.16—if you're running an earlier build, patching is high priority. If already on 4.7.16 or later, confirm no custom code reintroduced similar ACL flaws.
How can we tell if we've been exploited?
Review web server and LMS application logs from the past month for unauthenticated requests to admin or API endpoints, unexpected data modifications, or authorization failure events. Check user activity logs for changes made by accounts that should not have permission. Forensic review by a qualified analyst can determine if exploitation occurred and what was accessed.
Is this vulnerability in the CISA Known Exploited Vulnerabilities (KEV) catalog?
No, CVE-2025-64215 is not currently on the KEV list as of the published date. KEV status indicates in-the-wild active exploitation; absence does not mean the vulnerability is low-risk. Patch based on your own risk assessment and attack surface rather than KEV status alone.
This analysis is based on the published CVE record as of the modification date and vendor advisory information available at time of writing. Security teams should verify all version numbers, patch availability, and detailed attack vectors against the official StylemixThemes advisory and their own environment configuration. This page does not constitute security advice and should not replace consultation with your security team or vendor support. Real-world risk depends on network exposure, asset criticality, and custom configurations of your MasterStudy LMS Pro deployment. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2022-42479MEDIUMMissing Authorization in TemplateHouse Soledad – MEDIUM Severity Access Control Bypass
- CVE-2022-45813MEDIUMBeRocket Advanced AJAX Product Filters Missing Authorization Flaw
- CVE-2023-25969MEDIUMMissing Authorization in ThemeHunk Contact Form Plugin
- CVE-2023-32959MEDIUMMetroStore Missing Authorization Vulnerability – Patch Guide
- CVE-2025-12714MEDIUMRank Math SEO Plugin Unauthenticated Metadata Injection Vulnerability
- CVE-2025-52766MEDIUMMissing Authorization in Printeers Print & Ship – CVSS 6.5
- CVE-2025-53302MEDIUMMissing Authorization in Anton Shevchuk Constructor Framework
- CVE-2025-53346MEDIUMMissing Authorization in ThimPress Thim Core 2.3.3