CVE-2026-5060: The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D
mediumvulnerability
security
Summary
The MasterStudy LMS WordPress plugin (a tool for creating online courses) has a security flaw called Insecure Direct Object Reference in versions up to 3.7.14, where the `stm_lms_delete_cover()` function doesn't check if an instructor owns a file before deleting it. This allows instructors to delete any user's attachments by guessing file ID numbers.
Vulnerability Details
CVSS Score
6.5(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
network
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
July 29, 2026
Classification
Attack SophisticationModerate
Taxonomy References
CWE (Weakness Type)
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-5060
First tracked: July 29, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%