Description
WordPress Plugin MasterStudy LMS-for Online Courses and Education is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin MasterStudy LMS-for Online Courses and Education version 3.3.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.4 or latest
References
Related Vulnerabilities
Oracle JRE CVE-2018-2582 Vulnerability (CVE-2018-2582)
WordPress Plugin LearnDash LMS Cross-Site Scripting (3.1.1.1)
Mailman Other Vulnerability (CVE-2003-0992)
WordPress Plugin Advanced Search Cross-Site Scripting (1.1.2)
axios Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-42034)