Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.
Published: 2026-09-18
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted order manipulation
Action: Patch
AI Analysis

Impact

The MasterStudy LMS WordPress Plugin prior to version 3.7.50 performs no per‑object ownership or capability checks when orders are updated through its REST API. An authenticated user with the Instructor role can thus alter any order on the site, awarding free course access, revoking other users’ paid enrolments, and modifying order notes. This ability compromises the integrity of enrollment data and can lead to financial and operational losses.

Affected Systems

All installations of the MasterStudy LMS WordPress Plugin running a version older than 3.7.50 are vulnerable. The issue applies to the core plugin component and its REST API endpoints handling order updates.

Risk and Exploitability

The vulnerability carries a CVSS score of 3.8, indicating moderate severity, while the EPSS score is less than 1%, suggesting a low likelihood of exploitation at the time of analysis. It is not listed in the CISA KEV catalog. The likely attack vector involves the authenticated Instructor role sending crafted REST API requests; the required conditions are simple authentication and correct role assignment. Once exploited, an attacker can permanently alter enrollment state and undermine the learning platform’s revenue model.

Generated by OpenCVE AI on September 19, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the MasterStudy LMS plugin to version 3.7.50 or later to enforce per‑object ownership checks.
  • Revoke or limit the Instructor role’s permission to edit orders until the update is applied, reducing the attack surface.
  • Enable and monitor order‑change logs for the REST API, and audit logs to detect any unauthorized modifications.

Generated by OpenCVE AI on September 19, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Stylemix
Stylemix masterstudy Lms Wordpress Plugin
Wordpress-extensions
Wordpress-extensions masterstudy Lms
Vendors & Products Stylemix
Stylemix masterstudy Lms Wordpress Plugin
Wordpress-extensions
Wordpress-extensions masterstudy Lms

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.
Title MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR
References

Subscriptions

Stylemix Masterstudy Lms Wordpress Plugin
Wordpress-extensions Masterstudy Lms
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:13:38.917Z

Reserved: 2026-08-26T18:07:36.343Z

Link: CVE-2026-81340

cve-icon Vulnrichment

Updated: 2026-09-18T11:09:16.917Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:39.073

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-81340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:19Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key