WordPress Plugin Vulnerabilities

MasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course Discussions

Description

The plugin does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be leveraged for phishing and content spoofing against other users viewing the content.

Proof of Concept

Affects Plugins

References

Classification

Type
CONTENT INJECTION
OWASP top 10
CWE

Miscellaneous

Original Researcher
Jaime F. Murillo
Submitter
Jaime F. Murillo
Verified
Yes

Timeline

Publicly Published
2026-09-21 (about 3 days ago)
Added
2026-09-21 (about 2 days ago)
Last Updated
2026-09-21 (about 2 days ago)

Other