Impact
The Masteriyo LMS WordPress plugin before version 3.4.1 does not sanitize user-supplied metadata that is later deserialized. A subscriber or even an unauthenticated user can inject arbitrary PHP objects, and through a class bundled with the plugin, the attacker can write and execute code on the server. In the weaker form of the flaw, an attacker without an account can achieve arbitrary file writes, which can be the first step toward code execution or further compromise of the web application.
Affected Systems
Any installation of the Masteriyo LMS WordPress plugin older than 3.4.1 is affected. The vulnerability arises whenever the plugin processes metadata that originates from user input; no other vendor or product is implicated.
Risk and Exploitability
The EPSS score of < 1% indicates a very low but non‑zero likelihood that this flaw will be exploited in the wild, while the CVSS score of 9.9 reflects a high severity due to the potential for remote code execution. The vulnerability is not listed in CISA KEV. Attackers would need only a minimal subscriber account or no account at all to reach the deserialization point, making the attack surface broad. Successful exploitation leads to full control of the WordPress installation and potentially the underlying host.
OpenCVE Enrichment