ZeroHour

CVE-2026-62107

moderate

Unauthenticated PHP Object Injection in Masteriyo LMS WordPress Plugin

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-62107 is an unauthenticated PHP object injection vulnerability (CWE-502, deserialization of untrusted data) in the free Masteriyo LMS WordPress plugin, affecting all versions up to and including 3.4.0. An attacker can trigger it by sending a crafted request containing maliciously serialized PHP data to a plugin endpoint that unserializes untrusted input, without needing any login or privileges. Successful injection can let the attacker manipulate PHP objects, which may enable arbitrary code execution, data modification, or information disclosure depending on the gadget chains available on the site; the CVSS 8.8 rating reflects high confidentiality, integrity, and availability impact. Any WordPress site running Masteriyo LMS 3.4.0 or earlier is affected. No public proof of concept, in-the-wild exploitation, or CISA KEV listing is known at this time.

What to do: Upgrade Masteriyo LMS to a release newer than 3.4.0 as soon as the vendor's fix is published, and check the Patchstack advisory or plugin changelog for the exact fixed version number. Until patched, deactivate the plugin or restrict unauthenticated public access to it on internet-facing sites, since no login is required to trigger the flaw. No public PoC or in-the-wild exploitation is currently known, but monitor the advisory for updates and treat any exposed vulnerable site as potentially reachable by attackers once details emerge.

Affected
Masteriyo - LMS (WordPress plugin)<= 3.4.0
Estimated exposure
moderate~10,000 sites (plugin's WordPress.org active-install count is on the order of 10,000) — Masteriyo is a free WordPress.org LMS plugin with an active-install count on the order of ten thousand, and all sites running version 3.4.0 or earlier are in scope, so the exposed population is likely a few thousand to roughly ten thousand…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.