CVE-2025-7438: MasterStudy LMS – Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File Upload
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'installandactivateplugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability is difficult to exploit due to timing requirements and environmental factors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7438?
CVE-2025-7438 is considered a critical vulnerability due to the potential for arbitrary file uploads by authenticated users.
How do I fix CVE-2025-7438?
To fix CVE-2025-7438, update the MasterStudy LMS Pro plugin to version 4.8.0 or later.
Who is affected by CVE-2025-7438?
CVE-2025-7438 affects all versions of MasterStudy LMS Pro up to and including version 4.7.9.
What type of vulnerability is CVE-2025-7438?
CVE-2025-7438 is an arbitrary file upload vulnerability caused by insufficient file type validation.
What can attackers do with CVE-2025-7438?
Attackers can exploit CVE-2025-7438 to upload malicious files, potentially compromising the affected WordPress site.