{"id":"CVE-2026-88845","title":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…","summary":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…","severity":"none","cwe":["CWE-862"],"product":"MasterStudy LMS WordPress Plugin","affected":["masterstudy_lms_wordpress_plugin >= 2.3.0 < 3.7.50"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T06:17:03.313","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88845","references":[{"url":"https://wpscan.com/vulnerability/a1693fd3-7ba9-4a59-99ea-7f9fd00a9de1/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T06:39:26.614Z","slug":"CVE-2026-88845","body":"## Overview\n\nThe MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}