What is CVE-2026-5060?
CVE-2026-5060 is an Insecure Direct Object Reference (IDOR) vulnerability in the MasterStudy LMS WordPress plugin via the `stm_lms_delete_cover()` function. It affects all versions up to 3.7.14, allowing authenticated users to delete file covers belonging to other users by manipulating the `file_id` parameter. It is recommended to update the plugin to the latest version.
Azərbaycanca: CVE-2026-5060, MasterStudy LMS WordPress pluginində `stm_lms_delete_cover()` funksiyasında olan Insecure Direct Object Reference (IDOR) zəifliyidir. 3.7.14 versiyasına qədər bütün versiyaları təsir edir, autentifikasiya olunmuş istifadəçilərə `file_id` parametri vasitəsilə başqa istifadəçilərə məxsus fayl örtüklərini silməyə imkan verir. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which function of the MasterStudy LMS plugin was CVE-2026-5060 discovered?
This vulnerability was discovered in the `stm_lms_delete_cover()` function.
Does exploiting CVE-2026-5060 require authentication?
Yes, the vulnerability can be exploited by authenticated users via the `file_id` parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.