Impact
A classic Insecure Direct Object Reference flaw allows a user with the Instructor role to request the list of students for any course without first verifying that the course belongs to the instructor. The endpoint returns each enrolled student's name and email, resulting in the disclosure of personally identifiable information. The vulnerability is a direct read of protected data, not a code execution or denial of service. The impact is the compromise of confidential user data and potential future phishing or social engineering attacks against the disclosed students.
Affected Systems
The flaw exists in the MasterStudy LMS WordPress Plugin for versions prior to 3.7.50. Any WordPress installation that has the plugin installed and that assigns a user the Instructor role is affected. The plugin’s API endpoint that returns enrolled‑student data is the specific surface exposed. No other vendor products are listed as impacted.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity vulnerability focused on confidentiality. The EPSS score, being less than 1%, suggests that exploitation incidents are expected to be very rare. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported. An attacker would need legitimate Instructor credentials; no external user can trigger the data dump directly. Consequently, while the data exposed is sensitive, the overall risk to a system is low and would benefit from remediation.
OpenCVE Enrichment