Impact
The Masteriyo LMS WordPress plugin before version 3.4.1 fails to sanitise user‑supplied metadata that is later deserialized. A minimally privileged user can inject arbitrary PHP objects, and through a bundled class can write and execute code on the server. A weaker, account‑less form allows the attacker to write arbitrary files, enabling further compromise. This flaw provides full control over the web application and potentially the underlying server.
Affected Systems
The vulnerability affects the Masteriyo LMS WordPress plugin for any release earlier than 3.4.1. No other vendor or product is identified. The issue is present in all installations that use these older plugin versions and allow user‑supplied metadata to be deserialized.
Risk and Exploitability
The EPSS score of 0.00354 indicates a very low but non‑zero exploitation probability. The CVSS score is 9.9, reflective of high severity due to remote code execution. The attack vector is inferred to be server‑side deserialization of user‑supplied metadata, requiring only a minimal subscriber account or none for the weaker file‑write, modify, or delete files and run arbitrary PHP code, leading to full compromise of the WordPress installation and potentially the underlying host.
OpenCVE Enrichment