cleantalk
Vulnerabilities and Security Researches

MasterStudy LMS WordPress Plugin – for Online Courses and Education, CVE-2026-81342

CVE, Research URL

CVE-2026-81342

Published on
Aug 29, 2026
Research Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.
Affected versions
max 3.7.43.
Status
vulnerable