CVE-2026-88845: MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user can exploit it, including users with only the Subscriber role. The attacker does not need administrative privileges.
What does an attacker need to do to exploit it?
They need a valid account on the affected WordPress site and must be able to invoke the administrative maintenance action. No nonce or capability check protects that action in affected versions.
What is the impact of successful exploitation?
An attacker can trigger the demo import maintenance action to create published course and lesson content. The created content is attributed to the attacker’s own account.
Which versions are affected?
MasterStudy LMS versions before 3.7.50 are affected. Updating to version 3.7.50 or later addresses the described missing checks.