{"id":"CVE-2026-88846","published":"2026-09-24T06:17:03.437","lastModified":"2026-09-24T14:42:02.707","description":"The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled.","cvssScore":5.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/57b0dd3f-bd83-4fb7-b98d-c999026910cd/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}