Impact
The MasterStudy LMS WordPress Plugin before version 3.7.46 performs no authorization check before returning a student's learning statistics, allowing any unauthenticated user to retrieve course counts, points, certificates, quiz and assignment totals of any registered user. The exposed data is purely statistical but could reveal sensitive student progress, potentially aiding targeted phishing or social engineering attacks. The flaw is an information-disclosure issue and does not provide privilege escalation or remote execution.
Affected Systems
The affected product is the MasterStudy LMS plugin for WordPress; any installation using a version earlier than 3.7.46 is vulnerable. The flaw exists in the REST route /student/stats and no other products or versions are listed.
Risk and Exploitability
Because the flaw can be triggered without authentication via a publicly accessible REST endpoint, the attack surface is wide and no special access is required. While the EPSS score is not available and the vulnerability is not in the CISA KEV catalog, which implies no widespread exploitation yet, the potential privacy violation makes patching a high priority. The likely attack vector is any unauthenticated HTTP request to the /student/stats endpoint.
OpenCVE Enrichment