CVE-2026-81194: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retriev
mediumvulnerability
security
Summary
The MasterStudy LMS WordPress Plugin (a learning management system add-on for WordPress) before version 3.7.46 has a flaw where it doesn't properly check if a user is allowed to see certain data. This means any logged-in user, even those with minimal permissions like Subscribers, can view other instructors' course sales records if they know the right user ID to request.
Solution / Mitigation
Update the MasterStudy LMS WordPress Plugin to version 3.7.46 or later.
Vulnerability Details
CVSS Score
4.3(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
network
Attack Complexity
low
Privileges Required
low
User Interaction
none
Disclosure Date
September 2, 2026
Classification
Attack SophisticationTrivial
Taxonomy References
CWE (Weakness Type)
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81194
First tracked: September 2, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%