CVE-2026-82845
moderatePHP Object Injection RCE in Masteriyo LMS WordPress plugin (< 3.4.1)
The Masteriyo LMS WordPress plugin before 3.4.1 deserializes user-supplied metadata without validation when it is read back (CWE-502), enabling classic PHP object injection. An attacker holding even a minimal WordPress account (for example a subscriber created through open registration) can inject arbitrary PHP objects and, by abusing a gadget class bundled with the plugin's libraries, write and execute arbitrary code on the server. A weaker unauthenticated variant of the same flaw lets attackers with no account at all perform an arbitrary file write. The issue is rated critical at CVSS 3.1 9.9 with high impact on confidentiality, integrity, and availability, and affects all installations running versions before 3.4.1. The flaw was assigned via WPScan; no public proof of concept or in-the-wild exploitation is currently known.
What to do: Upgrade Masteriyo LMS to version 3.4.1 or later immediately, since both the authenticated RCE and the unauthenticated file-write paths are fixed there. If your site allows open self-registration, review recently created low-privilege (subscriber) accounts for suspicious signups and consider temporarily disabling registration. Audit the server for unexpected files under the web root, webshells, or newly added administrator users, and verify the integrity of wp-content and your backups.
| Masteriyo LMS (WordPress plugin) | before 3.4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.
- Ecosystems
- WordPress
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.