PT-2025-30008 · WordPress · Masterstudy Lms Pro

Thái An

·

Published

2025-07-18

·

Updated

2025-07-20

·

CVE-2025-7438

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MasterStudy LMS Pro versions up to and including 4.7.9
Description The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the install and activate plugin function. This allows authenticated attackers with Subscriber-level access and above to upload arbitrary files to the affected server, potentially leading to remote code execution. Exploitation is difficult due to timing requirements and environmental factors.
Recommendations MasterStudy LMS Pro versions prior to and including 4.7.9: Update to a version newer than 4.7.9.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-7438

Affected Products

Masterstudy Lms Pro