Impact
The MasterStudy LMS WordPress Plugin before version 3.7.46 does not properly verify authorization when retrieving order line-item data. This flaw allows any authenticated user, including those with Subscriber privileges, to access other instructors' course sales records by supplying a different instructor’s identifier. The impact is that sensitive sales information is disclosed to unauthorized users, representing a breach of confidentiality and an authorization bypass that aligns with CWE‑200 and CWE‑285 weaknesses.
Affected Systems
The vulnerability affects the MasterStudy LMS WordPress Plugin running on any WordPress installation. All versions earlier than 3.7.46 are susceptible, regardless of additional plugins or themes installed. The issue is tied to the plugin’s order-tracking functionality and specifically the handling of the author_id query parameter.
Risk and Exploitability
The vulnerability is exploitable by any authenticated user; the attack vector is inferred to be local to the WordPress site, requiring valid login credentials. No CVSS or EPSS score is provided, and the issue is not listed in the CISA KEV catalog, making the precise risk assessment difficult. Nevertheless, the potential for widespread information disclosure across all subscriber accounts warrants prompt remediation.
OpenCVE Enrichment