CVE-2026-88846: Unknown Masterstudy Lms WordPress Plugin

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled.

Affected products

  • Unknown Masterstudy Lms WordPress Plugin: from 2.3.0, before 3.7.50 (fixed in 3.7.50)

Published 2026-09-24. Last modified 2026-09-24.