Impact
The MasterStudy LMS WordPress plugin version 3.7.41 or earlier does not correctly enforce access controls on order billing data. An attacker who has the instructor role can request any order ID and receive the billing name, email, phone number, and postal address. This leads to unauthorized disclosure of personally identifiable information.
Affected Systems
All installations of the MasterStudy LMS WordPress plugin before version 3.7.42 are affected. The plugin is distributed by an unknown vendor and is typically used in WordPress sites that provide learning management services.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is sending standard HTTP requests to the order retrieval endpoint, enumerating order IDs. The vulnerability permits any account with the instructor role to view any order’s billing information. No additional exploit code is required beyond iterating order identifiers. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Disclosure of PII places affected sites in violation of privacy regulations. The impact scope is wide: any instructor can view any student's billing details. The CVSS score of 2.7 indicates low severity, but the exposure of sensitive PII remains a compliance concern.
OpenCVE Enrichment