medium · CVSS v3 6.5
CVE-2026-81340
The MasterStudy LMS WordPress Plugin before version 3.7.50 lacks proper per-object ownership and capability checks in its REST API order upd
Overview
The MasterStudy LMS WordPress Plugin before version 3.7.50 lacks proper per-object ownership and capability checks in its REST API order update functionality. This flaw allows authenticated users with the Instructor role to arbitrarily modify site orders, grant unauthorized free course enrollments, revoke paid user enrollments, and alter order notes. It poses a significant risk to data integrity and business logic within the learning management system.
Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.
Impact
The vulnerability primarily impacts integrity and availability by allowing unauthorized privilege escalation regarding course enrollments and order management. Instructors can bypass business logic to grant themselves or others free access to paid content and disrupt legitimate students' access by revoking their enrollments. Administrators and site owners face operational disruption, financial loss from bypassed payments, and reputational damage.
Remediation
Update the MasterStudy LMS WordPress Plugin to version 3.7.50 or later, where proper authorization and object-level capability checks are implemented. Audit existing user roles and permissions to ensure only trusted personnel hold the Instructor role. Review recent order history, enrollment logs, and order notes for unauthorized modifications.
Risk context
Rated with a medium severity CVSS v3 score of 6.5, this vulnerability requires authenticated access with specific privileges (Instructor role), reducing external exposure. However, because it directly impacts revenue and course access, prompt remediation is recommended for organizations utilizing the affected LMS plugin.
Affected products
- MasterStudy LMS WordPress Plugin < 3.7.50
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —