CVE-2026-81342
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.
- Published Aug 29, 2026
- CVSS 4.7 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available