CVE-2025-4800: MasterStudy LMS Pro <= 4.7.0 - Authenticated (Subscriber+) Arbitrary File Upload
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validation in the stmlmsaddassignmentattachment function in all versions up to, and including, 4.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server, which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4800?
CVE-2025-4800 has a high severity rating due to the potential for arbitrary file uploads, which can lead to various exploitation scenarios.
How do I fix CVE-2025-4800?
To mitigate CVE-2025-4800, update the MasterStudy LMS Pro plugin to version 4.7.1 or later where the issue is resolved.
Who is affected by CVE-2025-4800?
CVE-2025-4800 affects all versions of the MasterStudy LMS Pro plugin up to and including version 4.7.0 that are installed on WordPress sites.
What type of attack can be carried out exploiting CVE-2025-4800?
Exploiting CVE-2025-4800 allows authenticated attackers to upload arbitrary files, possibly leading to remote code execution.
Is authentication required to exploit CVE-2025-4800?
Yes, attackers need to be authenticated users with at least 'Subscriber' level permissions to exploit CVE-2025-4800.