CVE-2026-88844: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c
infovulnerability
security
Summary
The MasterStudy LMS WordPress Plugin (a learning management system add-on for WordPress) in versions before 3.7.50 has a security flaw where it doesn't check whether a user actually owns a course before showing them student enrollment data. This means instructors can see the names and email addresses of students in other instructors' courses, leaking private student information.
Solution / Mitigation
Update the MasterStudy LMS WordPress Plugin to version 3.7.50 or later.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
September 18, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-88844
First tracked: September 18, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 95%