Unrated severityNVD Advisory· Published Sep 24, 2026
CVE-2026-88846
CVE-2026-88846
Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated users to create accounts, and be logged into them, on sites where registration has been deliberately disabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.7.50
Patches
Vulnerability mechanics
References
1News mentions
1- WordPress: 25 Plugin Vulnerabilities Disclosed Together, Ranging from Critical to MediumVypr Intelligence · Sep 24, 2026