CVE-2026-62107
moderateUnauthenticated PHP Object Injection in Masteriyo LMS WordPress Plugin
CVE-2026-62107 is an unauthenticated PHP object injection vulnerability (CWE-502, deserialization of untrusted data) in the free Masteriyo LMS WordPress plugin, affecting all versions up to and including 3.4.0. An attacker can trigger it by sending a crafted request containing maliciously serialized PHP data to a plugin endpoint that unserializes untrusted input, without needing any login or privileges. Successful injection can let the attacker manipulate PHP objects, which may enable arbitrary code execution, data modification, or information disclosure depending on the gadget chains available on the site; the CVSS 8.8 rating reflects high confidentiality, integrity, and availability impact. Any WordPress site running Masteriyo LMS 3.4.0 or earlier is affected. No public proof of concept, in-the-wild exploitation, or CISA KEV listing is known at this time.
What to do: Upgrade Masteriyo LMS to a release newer than 3.4.0 as soon as the vendor's fix is published, and check the Patchstack advisory or plugin changelog for the exact fixed version number. Until patched, deactivate the plugin or restrict unauthenticated public access to it on internet-facing sites, since no login is required to trigger the flaw. No public PoC or in-the-wild exploitation is currently known, but monitor the advisory for updates and treat any exposed vulnerable site as potentially reachable by attackers once details emerge.
| Masteriyo - LMS (WordPress plugin) | <= 3.4.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.