Impact
The MasterStudy LMS WordPress Plugin fails to perform an authorization check before responding to the student-courses REST route, allowing any unauthenticated user to request and receive detailed enrollment and learning progress information for any registered student. This flaw, classified as a missing authorization check leading to information disclosure (CWE-200), directly exposes confidential user data and violates student privacy.
Affected Systems
Vendors: MasterStudy LMS WordPress Plugin. Product: MasterStudy LMS. Versions affected: all releases prior to 3.7.46.
Risk and Exploitability
The issue can be exploited by sending a simple HTTP request to the vulnerable endpoint, as no authentication or privilege verification is required. The CVSS score of 5.3 indicates a moderate confidentiality impact; attackers can harvest sensitive educational data. The EPSS score of 0.00145 (less than 1%) suggests a very low probability of exploitation, and the plugin is not listed in the CISA KEV catalog.
OpenCVE Enrichment