CVE-2026-68568: WordPress MasterStudy LMS plugin <= 3.7.41 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MasterStudy LMS pluginto a version that resolves this vulnerability.Fixed in 3.7.42
Event History
Frequently Asked Questions
Which installations should be treated as affected?
Sites using MasterStudy LMS plugin version 3.7.41 or earlier are affected according to the available information. The issue is a subscriber privilege-escalation flaw.
What level of access does an attacker need to exploit this?
An attacker needs an existing low-privileged subscriber account; no user interaction is required. The provided CVSS vector indicates the issue is remotely exploitable with low attack complexity.
Is there a documented mitigation if immediate patching is not possible?
The available information does not state whether the vulnerable behavior is enabled in a default configuration or identify any workaround. Updating beyond the affected version range should be prioritized when possible.