Impact
The MasterStudy LMS WordPress plugin allows an attacker to send a forged PayPal IPN message that is not checked for amount, receiver, currency or status before the plugin marks the order as completed. The result is that an unauthenticated user can trigger completion of a full‑price order by paying only a minimal token amount, immediately gaining access to paid content. This flaw is a classic bypass of the authorization process that lets attackers obtain paid resources without paying the required fee.
Affected Systems
It affects all installations of the MasterStudy LMS plugin that run a version older than 3.7.40. The plugin’s payment verification logic is vulnerable, and based on the description it is inferred that an attacker can exercise the flaw by sending a forged PayPal IPN message from any external address able to reach the plugin’s IPN endpoint exposed by the plugin.
Risk and Exploitability
Because a valid PayPal IPN signature and payment status are not validated, the vulnerability can be exploited by sending a crafted HTTP POST request to the IPN listener. Although EPSS is not available and the flaw is not listed in CISA KEV, the potential impact of unauthorized access to paid courses is significant. The lack of verification increases the likelihood of exploitation, especially on sites with active PayPal payment integration, and poses a high risk to both confidentiality and integrity of the paid content.
OpenCVE Enrichment