The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary attachments belonging to any user by enumerating sequential attachment IDs.
We have discovered 823 live websites that are affected by CVE-2026-5060.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 823 live websites (54% of Masterstudy LMS Learning Management System install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 114 versions ( 90% of all versions) |
| 187 websites | |
| 59 websites | |
| 46 websites | |
| 44 websites | |
| 43 websites | |
| 38 websites | |
| 32 websites | |
| 27 websites | |
| 24 websites | |
| 20 websites |
| .com | 342 websites |
| .org | 62 websites |
| .it | 30 websites |
| .com.br | 27 websites |
| .net | 23 websites |
| .es | 17 websites |
| .ru | 16 websites |
| .pl | 12 websites |
| .fr | 12 websites |
| .nl | 10 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.org | **,*** | ||
| ***********.***.co | ***,*** | ||
| *****.**************.com | ***,*** | ||
| ********.*******.***.cl | ***,*** | ||
| *********.institute | *,***,*** | ||
| *******.com | *,***,*** | ||
| *******.gr | *,***,*** | ||
| ******************.com | *,***,*** | ||
| *********************.it | *,***,*** | ||
| ****.**.ke | *,***,*** |
FAQ