CVE-2026-5060 | stylemix MasterStudy LMS Plugin up to 3.7.14 on WordPress stm_lms_delete_cover file_id resource injection (EUVD-2026-50271)
A vulnerability was found in stylemix MasterStudy LMS Plugin up to 3.7.14 on WordPress. It has been declared as problematic. The impacted element is the function stm_lms_delete_cover. The manipulation of the argument file_id results in improper control of resource identifiers.
This vulnerability was named CVE-2026-5060. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More