Impact
The MasterStudy LMS WordPress plugin prior to version 3.7.50 fails to validate that a member’s requested course is actually covered by the membership plan they hold, nor that the plan identifier supplied in the request matches an existing plan for the user. As a result, any user can enroll themselves in paid courses that are beyond their plan’s limits and in categories that should be restricted. The flaw is an administrative privilege escalation that allows members to override membership constraints, compromising the integrity and confidentiality of the course access control model.
Affected Systems
MasterStudy LMS WordPress plugin, versions starting with 1.9 and up to 3.7.49, inclusive. The issue applies only to sites running these plugin versions on WordPress. No specific vendor qualified product name was provided by the CNA, but the plugin is publicly available for WordPress installations.
Risk and Exploitability
The CVSS score of 4.2 classifies the vulnerability as medium severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited or no known exploitation. However, the attack vector is likely straightforward for authenticated users: an attacker can submit an enrollment request or modify form data to supply a plan identifier they do not possess, effectively convincing the plugin to grant access. The exploit requires the ability to trigger the enrollment logic, which is typically exposed to logged‑in members. Given the absence of denial of service or remote code execution capabilities, the risk is confined to unauthorized course content access, but it remains actionable by any plugin user.
OpenCVE Enrichment