Junglewise Threat Intelligence

CVE-2026-81338: MasterStudy LMS stored HTML injection in course discussions

CVE-2026-81338 · Severity: medium · CVSS 4.6 · Published 2026-09-23

Technologies: MasterStudy LMS. Vendors: MasterStudy.

Executive brief

MasterStudy LMS is a WordPress plugin that manages online courses and learning platforms. The plugin fails to properly filter user-submitted content in course discussions, allowing students and higher-level users to inject malicious HTML including iframes. Attackers can exploit this to conduct phishing attacks and impersonate site content to deceive other users viewing discussions.

Technical details

The plugin does not sanitize or restrict HTML in user-submitted content before storing and rendering it in course discussions. Subscribers and above-level WordPress users can inject arbitrary HTML and embed iframes, which persists and affects all subsequent viewers. The vulnerability requires user interaction from site visitors viewing the injected content, enabling phishing and content spoofing attacks.

Affected products

  • MasterStudy MasterStudy LMS before 3.7.50

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Fixed in version 3.7.50

References

Related threats