PT-2026-46129 · WordPress · Masterstudy Lms Pro Plus

·

CVE-2026-8653

·

Published

2026-06-04

·

Updated

2026-07-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MasterStudy LMS Pro Plus versions prior to 4.8.21
Description The MasterStudy LMS Pro Plus plugin for WordPress contains a generic SQL Injection flaw. This issue occurs because the columns parameter is not properly escaped and the SQL query is not sufficiently prepared. Authenticated attackers with instructor-level access or higher can append additional SQL queries to existing ones to extract sensitive information from the database.
Recommendations Update the plugin to a version later than 4.8.20. As a temporary workaround, restrict access to the columns parameter to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8653

Affected Products

Masterstudy Lms Pro Plus