Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of students enrolled in other instructors' courses.
Published: 2026-09-18
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality Disclosure
Action: Patch Immediately
AI Analysis

Impact

A classic Insecure Direct Object Reference flaw allows a user with the Instructor role to request the list of students for any course without first verifying that the course belongs to the instructor. The endpoint returns each enrolled student's name and email, resulting in the disclosure of personally identifiable information. The vulnerability is a direct read of protected data, not a code execution or denial of service. The impact is the compromise of confidential user data and potential future phishing or social engineering attacks against the disclosed students.

Affected Systems

The flaw exists in the MasterStudy LMS WordPress Plugin for versions prior to 3.7.50. Any WordPress installation that has the plugin installed and that assigns a user the Instructor role is affected. The plugin’s API endpoint that returns enrolled‑student data is the specific surface exposed. No other vendor products are listed as impacted.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity vulnerability focused on confidentiality. The EPSS score, being less than 1%, suggests that exploitation incidents are expected to be very rare. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported. An attacker would need legitimate Instructor credentials; no external user can trigger the data dump directly. Consequently, while the data exposed is sensitive, the overall risk to a system is low and would benefit from remediation.

Generated by OpenCVE AI on September 19, 2026 at 19:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MasterStudy LMS WordPress Plugin to version 3.7.50 or later, which validates course ownership before returning student data.
  • Restrict access to the enrollment data endpoint for instructors who do not own the course, for example by adding a custom role‑based access check or using a security plugin to block the endpoint until the plugin is updated.
  • Monitor web application logs for unauthorized requests to the enrollments endpoint and configure alerts for suspicious activity, ensuring that any data leaks are detected early.

Generated by OpenCVE AI on September 19, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Stylemix
Stylemix masterstudy Lms Wordpress Plugin
Wordpress
Wordpress wordpress
Vendors & Products Stylemix
Stylemix masterstudy Lms Wordpress Plugin
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of students enrolled in other instructors' courses.
Title MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR
References

Subscriptions

Stylemix Masterstudy Lms Wordpress Plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:08:43.091Z

Reserved: 2026-09-10T09:57:47.089Z

Link: CVE-2026-88844

cve-icon Vulnrichment

Updated: 2026-09-18T11:01:06.723Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:41.267

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-88844

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key