Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Arman Kumar

#33169of 57,348
8.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-98419
4.2
2026-09-25
WordPress · Masterstudy Lms · CVE-2026-88848
**Name of the Vulnerable Software and Affected Versions** MasterStudy LMS WordPress plugin versions 1.9 through 3.7.49 **Description** Insufficient verification occurs when a member requests enrollment in a course. The plugin fails to confirm if the requested course is included in the user's membership plan or if the submitted plan identifier is actually held by the user. This allows members to enroll in restricted paid courses that are not part of their plan or exceed the number of courses permitted by their membership. **Recommendations** Update MasterStudy LMS WordPress plugin to version 3.7.50 or later.
PT-2026-97715
4.3
2026-09-24
WordPress · Masterstudy Lms · CVE-2026-88847
**Name of the Vulnerable Software and Affected Versions** MasterStudy LMS WordPress Plugin versions prior to 3.7.50 **Description** An issue exists where the plugin fails to verify if a user is enrolled in a course before recording lesson completions. This allows any authenticated user, including those with subscriber privileges, to create course progress records for courses to which they have no authorized access. **Recommendations** Update MasterStudy LMS WordPress Plugin to version 3.7.50 or later.