CVE-2026-82845
Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection
CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
| Vendor | unknown |
| Product | masteriyo lms |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown masteriyo lms
Be the first to know when new critical vulnerabilities affecting unknown masteriyo lms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Masteriyo LMS
0 < 3.4.1
References
Credits
Karthik Ramakrishnan WPScan