WordPress Plugin Vulnerabilities
MasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course Discussions
Description
The plugin does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be leveraged for phishing and content spoofing against other users viewing the content.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
CONTENT INJECTION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Jaime F. Murillo
Submitter
Jaime F. Murillo
Submitter website
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-21 (about 3 days ago)
Added
2026-09-21 (about 2 days ago)
Last Updated
2026-09-21 (about 2 days ago)