CVE-2026-81198: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum
lowvulnerability
security
Summary
The MasterStudy LMS WordPress Plugin before version 3.7.46 has a security flaw where it doesn't properly check whether an instructor owns a curriculum (course structure) before letting them change it. This means an instructor can delete or modify course materials belonging to other instructors' courses.
Vulnerability Details
CVSS Score
3.8(low)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Attack Vector
network
Attack Complexity
low
Privileges Required
high
User Interaction
none
Disclosure Date
September 2, 2026
Classification
Attack SophisticationTrivial
Taxonomy References
CWE (Weakness Type)
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81198
First tracked: September 2, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%