Executive brief
Masteriyo LMS is a learning management system plugin for WordPress used to create and deliver online courses. An unauthenticated attacker can inject arbitrary PHP objects into the system, allowing them to execute malicious code on the server and compromise the website, including stealing data, installing backdoors, or taking over the entire site.
Technical details
The vulnerability is a PHP object injection (deserialization) flaw in Masteriyo LMS versions 3.4.0 and earlier. The vulnerability is unauthenticated and exploitable over the network, requiring no special privileges or user interaction. An attacker can craft malicious serialized PHP objects and inject them into the application, leading to arbitrary code execution on the server. The affected plugin versions are 3.4.0 and earlier; version 3.4.1 and later contain the fix. Exploitation of this vulnerability could enable complete server compromise and is expected to see active exploitation.
Affected products
- ThemeGrill Masteriyo LMS ≤ 3.4.0
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Version 3.4.1 released with fix