Impact
The MasterStudy LMS plugin for WordPress, in versions up to 3.7.42, contains an unauthenticated file deletion flaw. An attacker without any login credentials can delete any file accessible to the web server, potentially removing critical data, configuration files, or website assets. This vulnerability, identified as CWE-22, undermines the integrity of the site and can lead to data loss or extended downtime.
Affected Systems
Stylemix’s MasterStudy LMS plugin for WordPress versions 3.7.42 and earlier are affected. Site owners running these versions must verify they are not using version 3.7.42 or older and plan to update.
Risk and Exploitability
The flaw carries a CVSS score of 8.6, indicating high severity. Because the attack does not require authentication, the risk to any site is significant. EPSS data is currently unavailable, but the vulnerability’s presence in a widely used plugin and the lack of a KEV listing do not diminish its potential impact. An attacker could execute the deletion by simply visiting a crafted URL or by exploiting the plugin’s file deletion routine, thereby deleting arbitrary files on the server.
OpenCVE Enrichment