CVE-2026-57330: WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulnerability
Published Jun 29, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions.
Affected Software
1 affected component
MasterStudy MasterStudy LMS<=3.7.27
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MasterStudy LMS pluginto a version that resolves this vulnerability.Fixed in 3.7.28
Event History
Jun 29, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57330?
CVE-2026-57330 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-57330?
To fix CVE-2026-57330, update the MasterStudy LMS plugin to version 3.7.28 or later.
3
What type of vulnerability is CVE-2026-57330?
CVE-2026-57330 is a Cross Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-57330?
Users with the Subscriber role in WordPress are affected by CVE-2026-57330.
5
When was CVE-2026-57330 published?
CVE-2026-57330 was published on June 29, 2026.