CVE-2025-7438

HIGH

MasterStudy LMS Pro <= 4.7.9 - Authenticated Arbitrary File Upload via 'install_and_activate_plugin' Function

Title source: llm
STIX 2.1

Description

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability is difficult to exploit due to timing requirements and environmental factors.

Scores

CVSS v3 7.5
EPSS 0.0059
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
StylemixThemes/MasterStudy LMS Pro < 4.7.9
Published Jul 18, 2025
Tracked Since Feb 18, 2026