Impact
A REST route in the MasterStudy LMS WordPress Plugin does not verify authentication or filter by publication status, enabling any unauthenticated user to request the author‑specific course list. The returned data includes titles and IDs of courses that are draft, pending, or private, thereby exposing sensitive information about courses that the site owner intends to keep unreleased or hidden.
Affected Systems
WordPress sites running the Unknown:MasterStudy LMS WordPress Plugin before version 3.7.46 are affected. The vulnerability applies to all installations of the plugin where the default REST endpoint remains enabled and accessible to the public.
Risk and Exploitability
The vulnerability can be exercised remotely via a simple HTTP request to the exposed REST endpoint; no privileged access, secret credentials, or additional configuration is required. The EPSS score is not available, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The lack of authentication combined with an open endpoint makes the attack vector straightforward for an attacker to identify and exploit.
OpenCVE Enrichment