Impact
The vulnerability originates from insufficient input sanitization (CWE-345) in the MasterStudy LMS WordPress Plugin, allowing subscriber-level users to store raw HTML in course discussions. By embedding malicious iframes or other tags, an attacker can deliver phishing content or spoof legitimate activity, undermining user trust.
Affected Systems
Affected systems include any WordPress site running MasterStudy LMS version earlier than 3.7.50. The vulnerability is available to any user with a subscriber role or higher, such as instructors or administrators, who can post within course discussions.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate risk, and the EPSS score is reported as less than 1%, suggesting limited exploitation data. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to create or identify a subscriber account that can post discussion content; the exploit path is straightforward and does not require elevated privileges, making it relatively easy for internal users to target peers through the discussion interface.
OpenCVE Enrichment