SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81342

MEDIUM · CVSS 4.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The MasterStudy LMS WordPress plugin prior to version 3.7.43 is vulnerable due to improper validation of a redirect parameter during user registration, enabling unauthenticated attackers to redirect users to malicious external URLs. This flaw poses a significant risk of phishing attacks and user data exposure. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-81342
Severity
MEDIUM
CVSS
4.7
EPSS
0.17%
WordPress

Original NVD Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.