Impact
The MasterStudy LMS WordPress Plugin does not verify that a user is enrolled in a course before recording lesson completions, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to. This flaw enables users to falsify completion status, potentially gaining inappropriate access to advanced materials or skewing instructor reporting. The vulnerability represents an improper access control that can be abused to manipulate educational metrics and progress data.
Affected Systems
MasterStudy LMS WordPress Plugin, version 3.7.49 and earlier. No other vendors or products are listed as affected.
Risk and Exploitability
The vulnerability can be exploited by any authenticated user, requiring only normal login privileges but granting unauthorized modification of course completion data. EPSS information is not available, and the issue is not listed in the CISA KEV catalog, indicating a lower probability of widespread exploitation, yet the impact of creating fake progress records could be significant for institutions relying on accurate completion tracking. The risk level is moderate, contingent on the value placed on accurate course completion records and the number of users with subscriber roles.
OpenCVE Enrichment