Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MasterStudy LMS WordPress Plugin before version 3.7.46 performs no authorization check before returning a student's learning statistics, allowing any unauthenticated user to retrieve course counts, points, certificates, quiz and assignment totals of any registered user. The exposed data is purely statistical but could reveal sensitive student progress, potentially aiding targeted phishing or social engineering attacks. The flaw is an information-disclosure issue and does not provide privilege escalation or remote execution.

Affected Systems

The affected product is the MasterStudy LMS plugin for WordPress; any installation using a version earlier than 3.7.46 is vulnerable. The flaw exists in the REST route /student/stats and no other products or versions are listed.

Risk and Exploitability

Because the flaw can be triggered without authentication via a publicly accessible REST endpoint, the attack surface is wide and no special access is required. While the EPSS score is not available and the vulnerability is not in the CISA KEV catalog, which implies no widespread exploitation yet, the potential privacy violation makes patching a high priority. The likely attack vector is any unauthenticated HTTP request to the /student/stats endpoint.

Generated by OpenCVE AI on September 2, 2026 at 07:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MasterStudy LMS to version 3.7.46 or later.
  • If an immediate upgrade is not possible, restrict the /student/stats endpoint to authenticated or authorized users, for example by configuring the plugin or adding a firewall rule to block unauthenticated requests.
  • Disable or delete the REST route if it is not required for legitimate functionality.
  • Monitor for any unusual activity on the endpoint.

Generated by OpenCVE AI on September 2, 2026 at 07:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
Title MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T06:00:22.285Z

Reserved: 2026-08-26T16:31:44.413Z

Link: CVE-2026-81199

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T06:17:19.077

Modified: 2026-09-02T06:17:19.077

Link: CVE-2026-81199

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:45:03Z

Weaknesses