Insecure Direct Object Reference Vulnerability in MasterStudy LMS Plugin for WordPress
CVE-2026-5060
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-5060?
The MasterStudy LMS plugin for WordPress contains an Insecure Direct Object Reference vulnerability due to the lack of proper ownership verification in the stm_lms_delete_cover() function. This security flaw allows an authenticated attacker with Instructor-level access or higher to delete attachments indiscriminately by manipulating the sequential attachment IDs. It is critical for users of the plugin to update to the latest version to mitigate the risk of unauthorized deletion of user content.
Affected Version(s)
MasterStudy LMS WordPress Plugin β for Online Courses and Education 0 <= 3.7.23