Impact
The MasterStudy LMS WordPress Plugin fails to perform an authorization check before responding to the student-courses REST route, allowing any unauthenticated user to request and receive detailed enrollment and learning progress information for any registered student. This flaw, classified as a missing authorization check (CWE-285), directly exposes confidential user data and violates student privacy.
Affected Systems
Vendors: MasterStudy LMS WordPress Plugin. Product: MasterStudy LMS. Versions affected: all releases prior to 3.7.46.
Risk and Exploitability
The issue can be exploited by sending a simple HTTP request to the vulnerable endpoint, as no authentication or privilege verification is required. While no EPSS score or KEV listing is available, the flaw represents a high confidentiality risk; attackers can harvest sensitive educational data. The absence of a severity rating in the CVSS field suggests that the impact is primarily privacy leakage rather than system compromise, yet the ease of exploitation imposes a significant threat level.
OpenCVE Enrichment