THREAT OPS › Threat News › [NVD] CVE-2026-82845 (CRITICAL 9.9) — The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with
[NVD] CVE-2026-82845 (CRITICAL 9.9) — The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with
CVE-2026-82845 CVSS: 9.9 CRITICAL Published: 2026-09-12T06:16:26.043
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1,
Indicators of compromise
- CVE-2026-82845cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82845