WordPress · Masterstudy Lms · CVE-2026-81026
**Name of the Vulnerable Software and Affected Versions**
MasterStudy LMS WordPress Plugin versions prior to 3.7.40
**Description**
An issue exists where the plugin fails to verify the amount, receiver, currency, or status of a payment notification before marking an order as completed. This allows unauthenticated users to bypass payment requirements and gain access to paid content by paying only a token amount.
**Recommendations**
Update MasterStudy LMS WordPress Plugin to version 3.7.40 or later.