CVE-2026-4817Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'order' and 'orderby' parameters in the /lms/stm-lms/order/items REST API endpoint in versions up to and including 3.7.25. This is due to insufficient input sanitization combined with a design flaw in the custom Query builder class that allows unquoted SQL injection in ORDER BY clauses. When the Query builder detects parentheses in the sort_by parameter, it treats the value as a SQL function and directly concatenates it into the ORDER BY clause without any quoting. While esc_sql() is applied to escape quotes and backslashes, this cannot prevent ORDER BY injection when the values themselves are not wrapped in quotes in the resulting SQL statement. This makes it possible for authenticated attackers, with subscriber-level access and above, to append arbitrary SQL queries via the ORDER BY clause to extract sensitive information from the database including user credentials, session tokens, and other confidential data through time-based blind SQL injection techniques.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-17: 3PoC Mentioned / Linked · 2026-04-17: 1Exploit Tool / Code · 2026-04-17: 1Technical Details · 2026-04-17: 204-17
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4817 The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'order' and 'orderby'… https://www.cve.org/CVERecord?id=CVE-2026-4817

    Post summary

    A time‑based blind SQL injection was disclosed in the MasterStudy LMS WordPress plugin, affecting the 'order' and 'orderby' parameters.

    0000068
    57.2K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4817-masterstudy-lms-learning-management-system-version-3-7-25-medium-vulnerability-proof-of-concept CVE-2026-4817 #WordPress plugin #vulnerability masterstudy-lms-learning-management-system #cybersecurity #wordpressfirewall #wordpresss…

    Post summary

    The text links to a proof‑of‑concept for CVE‑2026‑4817, indicating that exploitation code exists, but there is no evidence of active attacks or a remediation solution.

    0000041
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4817 Time-Based Blind SQL Injection in MasterStudy LMS WordPress Plugin 3.7.25 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4817

    Post summary

    CVE-2026-4817 is a disclosed time-based blind SQL injection in MasterStudy LMS WordPress Plugin 3.7.25; no PoC, exploit, or patch information is provided.

    0000048
    4.0K followersView on X

Explore more