CVE-2026-73996: WordPress Masteriyo - LMS plugin <= 2.3.2 - Arbitrary File Upload vulnerability
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Masteriyo - LMS pluginto a version that resolves this vulnerability.Fixed in 2.3.3
Event History
Frequently Asked Questions
Which deployments are exposed?
Sites using the WordPress Masteriyo - LMS plugin at version 2.3.2 or earlier are affected. The issue is remotely exploitable over the network and does not require authentication or user interaction.
What access does an attacker need to exploit this?
An attacker does not need a WordPress account or any prior privileges. The CVSS vector indicates low attack complexity and no user interaction requirement.
Is there a documented remediation or temporary mitigation?
The provided information identifies affected versions through 2.3.2 but does not provide a fixed version, workaround, or mitigation. If patching cannot occur immediately, no specific compensating control is documented in the available data.