Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account.
Published: 2026-09-24
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized Content Creation by Non-Admin Users
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an authenticated user without sufficient privileges to invoke an administrative maintenance action—specifically a demo import—without any capability or nonce verification. As a result, such a user can create courses and lessons, and publish them as if they were the site owner, effectively gaining uncontrolled content creation capability. This flaw leads to unauthorized modification of site content, compromising the integrity and potentially the confidentiality of the site database.

Affected Systems

The affected product is the MasterStudy LMS WordPress Plugin released before version 3.7.50. Users running any earlier revision of this plugin—particularly those who have subscriber or other non-administrative roles—are vulnerable. There are no other vendors or product versions identified in the available data.

Risk and Exploitability

The flaw has a high severity from an exploitation standpoint because it requires only authentication and no further privileges or specialized knowledge. The EPSS score is not available, but the lack of a KEV listing suggests that active exploitation is not widespread yet. Nonetheless, once a user can write new content through the API of the plugin, the risk of defacement, spam, or information disclosure becomes significant. This is a classic example of missing authorization checks in an administrative function.

Generated by OpenCVE AI on September 24, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MasterStudy LMS plugin to version 3.7.50 or later, where proper capability checks have been added
  • Disallow the demo import feature for roles below Administrator by configuring the plugin’s role permissions or using a WordPress role mapper plugin
  • Implement a temporary block by disabling the demo import endpoint for all users through custom code or a firewall rule until the patch is applied

Generated by OpenCVE AI on September 24, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 24 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create published content on the site attributed to their own account.
Title MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-24T06:00:18.214Z

Reserved: 2026-09-10T09:58:01.350Z

Link: CVE-2026-88845

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T06:17:03.313

Modified: 2026-09-24T06:17:03.313

Link: CVE-2026-88845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T07:30:16Z

Weaknesses