Impact
The MasterStudy LMS WordPress Plugin before version 3.7.46 allows an authenticated user with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors. This flaw is an Insecure Direct Object Reference (IDOR) that enables a single instructor to tamper with peers’ instructional content, resulting in loss of data integrity and potential disruption of course delivery.
Affected Systems
WordPress sites running the MasterStudy LMS plugin at any release older than 3.7.46 are impacted. Users with the instructor role who have valid authentication credentials can target curriculum objects belonging to other instructors.
Risk and Exploitability
The EPSS score of <1% indicates a very low exploitation probability, and the CVSS score of 3.8 denotes moderate severity. The IDOR flaw allows any authenticated instructor to delete or modify curriculum objects owned by other instructors without additional privilege escalation. Because the vulnerability does not grant broader system compromise and is not listed in CISA KEV, the overall risk is moderate, but the integrity of instructional materials is still at risk if an instructor exploits the flaw.
OpenCVE Enrichment