CVE-2026-88846: MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disabled
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MasterStudy LMS WordPress Pluginto a version that resolves this vulnerability.Fixed in 3.7.50
Event History
Frequently Asked Questions
Which sites are exposed to unauthorized account creation?
Sites using a vulnerable MasterStudy LMS version before 3.7.50 are exposed if they have deliberately disabled WordPress user registration but retain an affected front-end registration flow.
What does an attacker need to exploit this issue?
An attacker does not need to authenticate. They can use one of the plugin's affected front-end registration flows to create and log into an account.
Does disabling site-wide registration prevent exploitation?
No. The vulnerability exists because the affected plugin versions do not check whether registration is enabled before creating the account through the affected front-end flow.