CVE-2026-81342: MasterStudy LMS < 3.7.43 - Unauthenticated Open Redirect
Published Aug 29, 2026
·Updated
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.
Affected Software
1 affected component
MasterStudy MasterStudy LMS WordPress Plugin<3.7.43
Event History
Aug 29, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker does not need to authenticate. They can supply a crafted redirect parameter during the user-registration flow to cause a user to be redirected to an arbitrary external URL.
2
Are installations running version 3.7.43 affected?
The issue affects versions before 3.7.43. Version 3.7.43 is not identified as affected by the provided information.