CRITICAL 9.8 CVE-2026-73996 Published 18 Aug 2026

Masteriyo LMS Plugin Unauthenticated Arbitrary File Upload Vulnerability

Worried this affects one of your servers?

The Masteriyo - LMS plugin is affected by an unauthenticated arbitrary file upload vulnerability.

Versions up to and including 2.3.2 are vulnerable.

An attacker who is not logged in can exploit this issue to upload arbitrary files.

Reference: CVE-2026-73996 on NVD

← Back to Security News