Impact
The vulnerability is an unauthenticated arbitrary file upload that allows attackers to place any file type into the WordPress Masteriyo LMS plugin directory. This flaw, identified as CWE‑434, could enable the execution of malicious code on the server, giving attackers remote code execution capabilities and full compromise of the site.
Affected Systems
WordPress sites running the Masteriyo – LMS plugin version 2.3.2 or earlier are affected. The vulnerability is present in all builds of the plugin up to 2.3.2, regardless of the WordPress core version, and includes the unofficial version identifiers masteriyo:Masteriyo – LMS.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and while the EPSS score is not available, the lack of a KEV listing does not reduce the risk. The path to exploitation is a straightforward file upload request that bypasses authentication checks, suggesting that the vulnerability can be triggered remotely with minimal technical effort. Attackers can then upload a malicious script and invoke it through the web interface.
OpenCVE Enrichment