Executive brief
MasterStudy LMS is a WordPress learning management system plugin used to deliver online courses. An unauthenticated attacker can delete arbitrary files from an affected website, causing data loss and complete site outage. This requires no authentication, meaning any internet user can exploit it.
Technical details
The vulnerability is an unauthenticated arbitrary file deletion vulnerability in MasterStudy LMS affecting versions 3.7.42 and earlier. The root cause involves a broken access control flaw (OWASP A1) that fails to properly validate user privileges before allowing file deletion operations. An attacker can send specially crafted requests over the network to delete critical files without any authentication or user interaction. This enables complete compromise of site availability and potential data destruction. The vulnerability was patched in version 3.7.43.
Affected products
- StylemixThemes MasterStudy LMS <=3.7.42
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: version 3.7.43