External risk intelligence

Masteriyo LMS WordPress Plugin Deserialization Vulnerability Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-82845

The vulnerability affects a WordPress plugin, which is a component of web applications commonly deployed as public-facing websites. Because the flaw is reachable via the web interface, it presents a surface that is routinely exposed to the public internet in standard deployment patterns.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability within the Masteriyo LMS WordPress plugin that could allow unauthorized users to execute arbitrary code or write files on the server. The issue stems from improper handling of user-supplied metadata, potentially leading to significant compromise of the affected web application and its underlying server. The primary concern is to confirm whether this specific plugin is in use and assess potential exposure.

  • Code execution or file write on server.
  • Critical flaw impacts public-facing websites.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending crafted data to a WordPress site using the Masteriyo LMS plugin. If the attacker has an account, they can inject malicious PHP objects that, when processed by the plugin, can lead to arbitrary code execution on the server. Without an account, an attacker can still achieve arbitrary file writes.

  • Requires authenticated user access.
  • Triggers PHP object deserialization.
  • Leads to code execution or file write.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in the Masteriyo LMS WordPress plugin could allow authenticated users to execute arbitrary PHP code on the server, potentially leading to unauthorized data access or modification. A less severe version of this issue, reachable without an account, could result in arbitrary file writes.

  • Server-side code execution.
  • User-supplied metadata can be deserialized.
  • Compromise of the WordPress site.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Masteriyo LMS WordPress plugin primarily impacts application owners and platform teams responsible for WordPress environments. The initial, critical step is to locate all instances of the affected plugin, assess their exposure and business criticality, and identify the specific accountable owner for each deployment. Remediation planning should then proceed based on this risk assessment.

  • Application owners should manage the issue.
  • Verify plugin presence and reachability.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Masteriyo LMS WordPress plugin?

Masteriyo LMS is a plugin used to build and manage online learning platforms and course content directly within the WordPress ecosystem. It provides features for creating lessons, quizzes, and managing student enrollment, essentially turning a WordPress site into a functional education portal.

How does CVE-2026-82845 work?

This vulnerability involves deserialization, classified as CWE-502. It occurs when the plugin takes data provided by a user and converts it back into complex PHP objects without proper validation. If a malicious user supplies specially crafted data, they can trick the plugin into performing unintended actions, such as executing unauthorized code or writing arbitrary files to the server.

What is required to trigger this vulnerability?

The most severe impact, remote code execution, requires the attacker to have at least a minimal user account on the WordPress site. Without any account, the vulnerability can still be triggered to perform arbitrary file writes, though this represents a less severe outcome than full code execution.

Why should I care about this vulnerability?

According to Halo Surface Signal, this vulnerability is particularly concerning because it affects a WordPress plugin typically deployed on public-facing websites. Because the flaw is reachable through the standard web interface, any internet-connected site running an unpatched version of the plugin presents an accessible target for exploitation.

What should I do if I use Masteriyo LMS?

The immediate priority is to identify all WordPress instances where the Masteriyo LMS plugin is installed. Once you have a list of deployments, verify which sites are running versions older than 3.4.1. Coordinate with your platform teams to assess the business risk of these sites and plan an update to a secure version as soon as possible.

References