Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be leveraged for phishing and content spoofing against other users viewing the content. | |
| Title | MasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course Discussions | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:59:21.227Z
Reserved: 2026-08-26T18:07:02.182Z
Link: CVE-2026-81338
Updated: 2026-09-23T10:38:19.786Z
Status : Received
Published: 2026-09-23T06:17:02.150
Modified: 2026-09-23T11:17:11.727
Link: CVE-2026-81338
No data.
OpenCVE Enrichment
Updated: 2026-09-23T15:30:07Z
-
CWE-345
Insufficient Verification of Data Authenticity