CVE-2026-62107: WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
Affected Software
1 affected component
WordPress Masteriyo - LMS Plugin<=3.4.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Masteriyo - LMS Pluginto a version that resolves this vulnerability.Fixed in 3.4.1
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Do attackers need a WordPress account to exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need to authenticate to WordPress to attempt exploitation.
2
Which deployments should be prioritized for investigation?
Prioritize WordPress sites using the Masteriyo - LMS plugin at version 3.4.0 or earlier. The provided data does not specify configuration-based exclusions.