CVE-2026-78284: WordPress MasterStudy LMS plugin <= 3.7.42 - Arbitrary File Deletion vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Affected Software
1 affected component
WordPress MasterStudy LMS<=3.7.42
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MasterStudy LMS pluginto a version that resolves this vulnerability.Fixed in 3.7.43
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
2
Which installations are affected?
MasterStudy LMS versions 3.7.42 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration is required.
3
What is the likely impact of successful exploitation?
Successful exploitation allows arbitrary file deletion. The CVSS vector indicates high availability impact and scope change, while no confidentiality or integrity impact is listed.