CVE-2026-62107

8.8

Masteriyo · Masteriyo - LMS

The Masteriyo LMS plugin for WordPress is vulnerable to unauthenticated PHP object injection, allowing attackers to execute arbitrary code.

Executive summary

A critical PHP object injection vulnerability in the Masteriyo LMS plugin for WordPress allows unauthenticated attackers to potentially compromise the entire application.

Vulnerability

This vulnerability involves the deserialization of untrusted data, specifically through a PHP object injection flaw. An unauthenticated attacker can leverage this weakness to achieve remote code execution or other unauthorized actions within the WordPress environment.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational data and system integrity. Because it allows for remote code execution, an attacker could gain full control over the affected WordPress installation, leading to potential data breaches, administrative account takeover, or complete site defacement. The CVSS score of 8.8 reflects the high severity of this flaw, as it facilitates significant impact on confidentiality, integrity, and availability.

Remediation

Immediate Action: Update the Masteriyo LMS plugin to version 3.4.1 or the latest available version provided by the vendor.

Proactive Monitoring: Review web server access logs for anomalous PHP requests or unusual serialized data patterns that may indicate injection attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) configured with rules to detect and block malicious deserialization payloads targeting WordPress plugins.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system compromise, administrators must prioritize patching this vulnerability immediately. Ensure that the Masteriyo LMS plugin is updated to version 3.4.1 or higher across all affected environments to eliminate the injection risk. Failure to apply this update leaves the application susceptible to full unauthorized access.

More Masteriyo CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by 20kilograma | Patchstack Bug Bounty Program, per the CVE Program record.