Impact
The MasterStudy LMS WordPress Plugin before version 3.7.46 allows authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors. This is a classic Insecure Direct Object Reference flaw, permitting a single instructor to tamper with peers’ instructional content. The impact is direct loss of data integrity and potential disruption of course delivery for affected instructors.
Affected Systems
WordPress sites running the MasterStudy LMS plugin at any release older than 3.7.46 are impacted. Users with the instructor role who have valid authentication credentials can target curriculum objects belonging to other instructors.
Risk and Exploitability
While EPSS data is not available, KEV is not listed. The vulnerability is straightforward to exploit: an authenticated instructor simply manipulates the curriculum ID submitted to the plugin without any ownership checks. The lack of an elevation requirement and the presence of a privileged role mean that any instructor can perform destructive or tampering actions on another instructor’s content. Consequently, the risk is high for sites relying heavily on the MasterStudy LMS plugin without additional access controls.
OpenCVE Enrichment