Unauthenticated Arbitrary File Deletion Vulnerability in MasterStudy LMS by MasterStudy
CVE-2026-78284

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78284?

The MasterStudy LMS plugin is susceptible to an unauthenticated arbitrary file deletion vulnerability, which allows attackers to exploit the system and remove files without proper authentication. This issue affects versions of the plugin up to and including 3.7.42, potentially compromising sensitive data and disrupting service functionality. It is crucial for users to be vigilant and apply necessary patches or updates to mitigate risks.

Affected Version(s)

MasterStudy LMS <= 3.7.42

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

20kilograma | Patchstack Bug Bounty Program
.