CRITICAL 9.9 CVE-2026-82845 Published 12 Sept 2026

Masteriyo LMS WordPress Plugin Code Execution Vulnerability

Worried this affects one of your servers?

The Masteriyo LMS WordPress plugin, before version 3.4.1, has a security flaw that allows users with minimal accounts to inject and execute arbitrary PHP code on the server.

This is due to the plugin not preventing user-supplied values held as metadata from being deserialized when they are read back. A weaker form of the same issue is reachable without an account and allows an arbitrary file write.

Reference: CVE-2026-82845 on NVD

← Back to Security News