OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-88843

HIGH · CVSS 7.2 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The MasterStudy LMS WordPress Plugin prior to version 3.7.50 is vulnerable due to inadequate validation of a display-style setting, enabling users with Contributor roles and higher to include and execute arbitrary local PHP files on the server. This flaw poses a significant risk, as it can lead to remote code execution, potentially compromising the integrity and security of the affected WordPress installations. WordPress site administrators and developers utilizing this plugin should prioritize immediate updates to mitigate this high-severity vulnerability.

CVE
CVE-2026-88843
Severity
HIGH
CVSS
7.2
EPSS
0.36%
WordPress

Original NVD Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an earlier release and this one was not, so the issue persists in versions the earlier advisory reports as fixed.