CVE-2026-88846: MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disabled

Published Sep 24, 2026
·
Updated

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled.

Affected Software

1 affected component
StylemixThemes MasterStudy LMS>=2.3.0<3.7.50

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MasterStudy LMS WordPress Plugin to a version that resolves this vulnerability.

    Fixed in 3.7.50

Event History

Sep 24, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description

Frequently Asked Questions

1

Which sites are exposed to unauthorized account creation?

Sites using a vulnerable MasterStudy LMS version before 3.7.50 are exposed if they have deliberately disabled WordPress user registration but retain an affected front-end registration flow.

2

What does an attacker need to exploit this issue?

An attacker does not need to authenticate. They can use one of the plugin's affected front-end registration flows to create and log into an account.

3

Does disabling site-wide registration prevent exploitation?

No. The vulnerability exists because the affected plugin versions do not check whether registration is enabled before creating the account through the affected front-end flow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203