
CVE-2026-0559 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stm_lms_cour… https://www.cve.org/CVERecord?id=CVE-2026-0559
Post summary
A Stored Cross‑Site Scripting (XSS) vulnerability (CVE-2026-0559) affecting the MasterStudy LMS WordPress plugin has been disclosed, but no PoC, exploit, patch, or evidence of active exploitation is provided.

