Impact
The vulnerability is an indirect object reference that allows any authenticated user with a Subscriber role to read quiz attempt results belonging to other users. By supplying another user's attempt ID, the plugin returns score, pass/fail status, and timestamps. This results in confidentiality compromise of educational data and corresponds to CWE‑639.
Affected Systems
Any installation of the MasterStudy LMS WordPress Plugin running a version earlier than 3.7.50 is susceptible. The affected product is a WordPress plugin offered by the unknown provider MasterStudy LMS.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is not known. Successful exploitation requires the attacker to be an authenticated subscriber and to supply a valid attempt identifier, which may need ID enumeration or prior knowledge. Because the plugin does not enforce per‑object ownership checks, legitimate subscribers can read other students' quiz data as long as they possess any attempt ID.
OpenCVE Enrichment