Unauthenticated Arbitrary File Deletion Vulnerability in MasterStudy LMS by MasterStudy
CVE-2026-78284
8.6HIGH
What is CVE-2026-78284?
The MasterStudy LMS plugin is susceptible to an unauthenticated arbitrary file deletion vulnerability, which allows attackers to exploit the system and remove files without proper authentication. This issue affects versions of the plugin up to and including 3.7.42, potentially compromising sensitive data and disrupting service functionality. It is crucial for users to be vigilant and apply necessary patches or updates to mitigate risks.
Affected Version(s)
MasterStudy LMS <= 3.7.42