Impact
The vulnerability allows an authenticated user without sufficient privileges to invoke an administrative maintenance action—specifically a demo import—without any capability or nonce verification. As a result, such a user can create courses and lessons, and publish them as if they were the site owner, effectively gaining uncontrolled content creation capability. This flaw leads to unauthorized modification of site content, compromising the integrity and potentially the confidentiality of the site database.
Affected Systems
The affected product is the MasterStudy LMS WordPress Plugin released before version 3.7.50. Users running any earlier revision of this plugin—particularly those who have subscriber or other non-administrative roles—are vulnerable. There are no other vendors or product versions identified in the available data.
Risk and Exploitability
The flaw has a high severity from an exploitation standpoint because it requires only authentication and no further privileges or specialized knowledge. The EPSS score is not available, but the lack of a KEV listing suggests that active exploitation is not widespread yet. Nonetheless, once a user can write new content through the API of the plugin, the risk of defacement, spam, or information disclosure becomes significant. This is a classic example of missing authorization checks in an administrative function.
OpenCVE Enrichment