Executive brief
MasterStudy LMS is a WordPress plugin that manages online courses and learning platforms. The plugin fails to properly filter user-submitted content in course discussions, allowing students and higher-level users to inject malicious HTML including iframes. Attackers can exploit this to conduct phishing attacks and impersonate site content to deceive other users viewing discussions.
Technical details
The plugin does not sanitize or restrict HTML in user-submitted content before storing and rendering it in course discussions. Subscribers and above-level WordPress users can inject arbitrary HTML and embed iframes, which persists and affects all subsequent viewers. The vulnerability requires user interaction from site visitors viewing the injected content, enabling phishing and content spoofing attacks.
Affected products
- MasterStudy MasterStudy LMS before 3.7.50
Timeline
- 2026-09-21: disclosed
- 2026-09-23: patched: Fixed in version 3.7.50