Impact
The MasterStudy LMS WordPress Plugin prior to version 3.7.50 performs no per‑object ownership or capability checks when orders are updated through its REST API. An authenticated user with the Instructor role can thus alter any order on the site, awarding free course access, revoking other users’ paid enrolments, and modifying order notes. This ability compromises the integrity of enrollment data and can lead to financial and operational losses.
Affected Systems
All installations of the MasterStudy LMS WordPress Plugin running a version older than 3.7.50 are vulnerable. The issue applies to the core plugin component and its REST API endpoints handling order updates.
Risk and Exploitability
The vulnerability carries a CVSS score of 3.8, indicating moderate severity, while the EPSS score is less than 1%, suggesting a low likelihood of exploitation at the time of analysis. It is not listed in the CISA KEV catalog. The likely attack vector involves the authenticated Instructor role sending crafted REST API requests; the required conditions are simple authentication and correct role assignment. Once exploited, an attacker can permanently alter enrollment state and undermine the learning platform’s revenue model.
OpenCVE Enrichment