CVE-2026-81200: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order informa
infovulnerability
security
Summary
The MasterStudy LMS WordPress Plugin (a learning management system tool for WordPress) before version 3.7.42 has a security flaw where instructors can access other users' order billing information like names, emails, phone numbers, and addresses by guessing order ID numbers. This happens because the plugin doesn't properly check whether a user should be allowed to view that data before showing it to them.
Solution / Mitigation
Update the MasterStudy LMS WordPress Plugin to version 3.7.42 or later.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.1%
Disclosure Date
August 29, 2026
Classification
Attack SophisticationTrivial
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81200
First tracked: August 29, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%