WordPress · Masterstudy Lms · CVE-2026-88847
**Name of the Vulnerable Software and Affected Versions**
MasterStudy LMS WordPress Plugin versions prior to 3.7.50
**Description**
An issue exists where the plugin fails to verify if a user is enrolled in a course before recording lesson completions. This allows any authenticated user, including those with subscriber privileges, to create course progress records for courses to which they have no authorized access.
**Recommendations**
Update MasterStudy LMS WordPress Plugin to version 3.7.50 or later.