Description
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
Published: 2026-09-12
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

The Masteriyo LMS WordPress plugin before version 3.4.1 does not sanitize user-supplied metadata that is later deserialized. A subscriber or even an unauthenticated user can inject arbitrary PHP objects, and through a class bundled with the plugin, the attacker can write and execute code on the server. In the weaker form of the flaw, an attacker without an account can achieve arbitrary file writes, which can be the first step toward code execution or further compromise of the web application.

Affected Systems

Any installation of the Masteriyo LMS WordPress plugin older than 3.4.1 is affected. The vulnerability arises whenever the plugin processes metadata that originates from user input; no other vendor or product is implicated.

Risk and Exploitability

The EPSS score of < 1% indicates a very low but non‑zero likelihood that this flaw will be exploited in the wild, while the CVSS score of 9.9 reflects a high severity due to the potential for remote code execution. The vulnerability is not listed in CISA KEV. Attackers would need only a minimal subscriber account or no account at all to reach the deserialization point, making the attack surface broad. Successful exploitation leads to full control of the WordPress installation and potentially the underlying host.

Generated by OpenCVE AI on September 15, 2026 at 18:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Masteriyo LMS plugin to version 3.4.1 or newer.
  • Disable or remove the feature that deserializes user-supplied metadata to block the injection path.
  • Ensure file write permissions are restricted so that the plugin cannot write files outside of its intended directories.

Generated by OpenCVE AI on September 15, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
Title Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:33:08.896Z

Reserved: 2026-08-31T08:27:16.968Z

Link: CVE-2026-82845

cve-icon Vulnrichment

Updated: 2026-09-12T15:22:05.722Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:26.043

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-82845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data