---
id: CVE-2026-88843
title: >-
  The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not
  validate one of its display-style settings before using it to build a template
  path, allowing users with the Contributor role and above to include and
  execute …
summary: >-
  The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not
  validate one of its display-style settings before using it to build a template
  path, allowing users with the Contributor role and above to include and
  execute …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
product: MasterStudy LMS WordPress Plugin
affected:
  - masterstudy_lms_wordpress_plugin >= 3.5.29 < 3.7.50
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:42:02.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88843'
references:
  - url: 'https://wpscan.com/vulnerability/fffc0d8c-256e-417d-b76c-251948b9f1ed/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T10:35:02.540672Z'
ingestedAt: '2026-09-24T06:39:26.613Z'
epss: 0.00359
epssPercentile: 0.26997
---

## Overview

The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute arbitrary local PHP files on the server. An equivalent path was corrected in an earlier release and this one was not, so the issue persists in versions the earlier advisory reports as fixed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
