A critical SQL injection vulnerability was discovered in the Motors plugin, affecting versions up to 1.4.109. This vulnerability allows for blind SQL injection, potentially enabling attackers to extract sensitive data from the database. The vulnerability has a CVSS score of 9.3 and is considered critical. The issue was publicly disclosed on June 17, 2026, and patched shortly after. Users of the Motors plu [truncated]
The CVE-2026-54814 vulnerability is a PHP Remote File Inclusion issue in the Motors plugin, affecting versions up to 1.4.109. This vulnerability allows attackers to include local or remote files, potentially leading to code execution. The vulnerability has a CVSS score of 8.1, indicating high severity. Users of the Motors plugin should update to a patched version as soon as possible. The vulnerability was [truncated]
A Subscriber SQL Injection vulnerability was discovered in MasterStudy LMS versions up to 3.7.25. This vulnerability allows attackers to inject malicious SQL code, potentially leading to unauthorized data access or modification. The CVSS score for this vulnerability is 8.5, indicating HIGH severity. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].
A Subscriber Broken Access Control vulnerability exists in the Motors plugin for WordPress versions less than 1.4.107. This vulnerability has been assigned a CVSS score of 6.5, indicating a MEDIUM severity level. The vulnerability allows an attacker to bypass access controls, potentially leading to unauthorized actions. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-862.
A Missing Authorization vulnerability was discovered in StylemixThemes MasterStudy LMS Pro, affecting versions from n/a before 4.7.16. This vulnerability allows attackers to access functionality not properly constrained by Access Control Lists (ACLs). The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 6.5, indicating a Medium severity level.