CRITICAL
9.9 CVE-2026-82845 Published 12 Sept 2026
Masteriyo LMS WordPress Plugin Code Execution Vulnerability
Worried this affects one of your servers?
The Masteriyo LMS WordPress plugin, before version 3.4.1, has a security flaw that allows users with minimal accounts to inject and execute arbitrary PHP code on the server.
This is due to the plugin not preventing user-supplied values held as metadata from being deserialized when they are read back. A weaker form of the same issue is reachable without an account and allows an arbitrary file write.
Reference: CVE-2026-82845 on NVD
← Back to Security News