PT-2026-95231 · WordPress · Masterstudy Lms

·

CVE-2026-81340

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions MasterStudy LMS WordPress Plugin versions prior to 3.7.50
Description Insufficient per-object ownership or capability checks occur when updating orders via the REST API. This allows users with the Instructor role to modify any order on the site, which can lead to granting free course enrolment, revoking paid enrolments of other users, and tampering with order notes.
Recommendations Update MasterStudy LMS WordPress Plugin to version 3.7.50 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81340

Affected Products

Masterstudy Lms