Description
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Published: 2026-08-24
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted File Deletion
Action: Patch Immediately
AI Analysis

Impact

The MasterStudy LMS plugin for WordPress, in versions up to 3.7.42, contains an unauthenticated file deletion flaw. An attacker without any login credentials can delete any file accessible to the web server, potentially removing critical data, configuration files, or website assets. This vulnerability, identified as CWE-22, undermines the integrity of the site and can lead to data loss or extended downtime.

Affected Systems

Stylemix’s MasterStudy LMS plugin for WordPress versions 3.7.42 and earlier are affected. Site owners running these versions must verify they are not using version 3.7.42 or older and plan to update.

Risk and Exploitability

The flaw carries a CVSS score of 8.6, indicating high severity. Because the attack does not require authentication, the risk to any site is significant. EPSS data is currently unavailable, but the vulnerability’s presence in a widely used plugin and the lack of a KEV listing do not diminish its potential impact. An attacker could execute the deletion by simply visiting a crafted URL or by exploiting the plugin’s file deletion routine, thereby deleting arbitrary files on the server.

Generated by OpenCVE AI on August 24, 2026 at 22:47 UTC.

Remediation

Vendor Solution

Update the WordPress MasterStudy LMS Plugin to the latest available version (at least 3.7.43).


OpenCVE Recommended Actions

  • Upgrade the MasterStudy LMS plugin to the latest version (at least 3.7.43).
  • Restrict the web server’s file permissions so that the plugin can delete files only within its allowed directories.
  • Maintain regular backups of the site and verify the ability to restore from them to mitigate data loss.

Generated by OpenCVE AI on August 24, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Title WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-25T14:42:01.677Z

Reserved: 2026-08-24T07:38:04.148Z

Link: CVE-2026-78284

cve-icon Vulnrichment

Updated: 2026-08-25T14:41:56.654Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T22:17:21.053

Modified: 2026-08-26T16:19:05.917

Link: CVE-2026-78284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:00:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')