CVE-2026-88846
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled.
- Published Sep 24, 2026
- CVSS 5.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available