Arbitrary File Upload Vulnerability in MasterStudy LMS Pro Plugin
CVE-2025-4800
8.8HIGH
What is CVE-2025-4800?
The MasterStudy LMS Pro plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation within the stm_lms_add_assignment_attachment function. This vulnerability affects all versions up to and including 4.7.0. Authenticated attackers with Subscriber-level access and above can exploit this flaw to upload unauthorized files on the server, potentially leading to remote code execution and severe security breaches.
Affected Version(s)
MasterStudy LMS Pro * <= 4.7.0