Description
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated arbitrary file upload that allows attackers to place any file type into the WordPress Masteriyo LMS plugin directory. This flaw, identified as CWE‑434, could enable the execution of malicious code on the server, giving attackers remote code execution capabilities and full compromise of the site.

Affected Systems

WordPress sites running the Masteriyo – LMS plugin version 2.3.2 or earlier are affected. The vulnerability is present in all builds of the plugin up to 2.3.2, regardless of the WordPress core version, and includes the unofficial version identifiers masteriyo:Masteriyo – LMS.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, and while the EPSS score is not available, the lack of a KEV listing does not reduce the risk. The path to exploitation is a straightforward file upload request that bypasses authentication checks, suggesting that the vulnerability can be triggered remotely with minimal technical effort. Attackers can then upload a malicious script and invoke it through the web interface.

Generated by OpenCVE AI on August 18, 2026 at 16:48 UTC.

Remediation

Vendor Solution

Update the WordPress Masteriyo - LMS Plugin to the latest available version (at least 2.3.3).


OpenCVE Recommended Actions

  • Update the Masteriyo LMS plugin to version 2.3.3 or later.
  • Disable or deactivate the Masteriyo LMS plugin until the patch is applied.
  • Remove or quarantine any files uploaded during the vulnerable interval and verify that no malicious scripts remain in the upload directory.

Generated by OpenCVE AI on August 18, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress
Vendors & Products Masteriyo
Masteriyo masteriyo
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Title WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Masteriyo Masteriyo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:10:57.008Z

Reserved: 2026-08-14T10:15:59.205Z

Link: CVE-2026-73996

cve-icon Vulnrichment

Updated: 2026-08-18T15:10:07.867Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:08.600

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:18:54Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type