Arbitrary File Execution in MasterStudy LMS Plugin by Webnus
CVE-2026-88843
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-88843?
The MasterStudy LMS WordPress Plugin prior to version 3.7.50 is vulnerable due to improper validation of display-style settings. This flaw permits users with Contributor roles or above to include and execute arbitrary local PHP files on the server. Notably, a similar path issue was addressed in an earlier release, yet this specific vulnerability remains unpatched, posing significant risks to site integrity and security.
Affected Version(s)
MasterStudy LMS WordPress Plugin 3.5.29 < 3.7.50
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.