CVE-2026-5060

MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the `file_id` parameter before passing it to `wp_delete_attachment()`. This makes it possible for authenticated attackers, with Instructor-level access and above, to delete arbitrary attachments belonging to any user by enumerating sequential attachment IDs.


We have discovered 823 live websites that are affected by CVE-2026-5060.

Run a Free Instant Scan




Affected Software

Product  Masterstudy LMS Learning Management System
Category Wordpress Plugins
Vulnerable Domains823 live websites (54% of Masterstudy LMS Learning Management System install base)
Vulnerable Versions
  • from 0 through 3.7.23
Vulnerable Versions Count114 versions ( 90% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 29, 2026
  • Updated - Jul 29, 2026

Credits

  • Md. Moniruzzaman Prodhan (NomanProdhan) (finder)

Website Distribution by Country

Number of websites using CVE-2026-5060
United States187 websites



Germany59 websites
GB46 websites
Spain44 websites
Italy43 websites
France38 websites
Brazil32 websites
India27 websites
Cyprus24 websites
Russia20 websites

Website Distribution by TLD

Number of websites using CVE-2026-5060
.com342 websites
.org62 websites
.it30 websites
.com.br27 websites
.net23 websites
.es17 websites
.ru16 websites
.pl12 websites
.fr12 websites
.nl10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-5060

Top websites that are affected by CVE-2026-5060. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org United States**,***
***********.***.co Colombia***,***
*****.**************.com United States***,***
********.*******.***.cl Chile***,***
*********.institute United States*,***,***
*******.com Malaysia*,***,***
*******.gr Greece*,***,***
******************.com United States*,***,***
*********************.it Italy*,***,***
****.**.ke GB*,***,***
See full domain list

FAQ

CVE-2026-5060 is Authorization Bypass Through User-Controlled Key in Masterstudy LMS Learning Management System
A total of 823 websites have been identified as vulnerable to CVE-2026-5060, based on global website indexing conducted by WebTechSurvey.
The Masterstudy LMS Learning Management System is affected by the CVE-2026-5060 vulnerability.
Masterstudy LMS Learning Management System versions up to and including 3.7.23 are vulnerable to CVE-2026-5060.