CVE-2026-81196: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question
lowvulnerability
security
Summary
The MasterStudy LMS WordPress Plugin (a learning management system add-on for WordPress) before version 3.7.46 has a security flaw where it doesn't properly check if an instructor owns a quiz question before letting them view it. This means an instructor can read other instructors' quiz questions, including the answers and explanations, which they shouldn't be able to access.
Solution / Mitigation
Update the MasterStudy LMS WordPress Plugin to version 3.7.46 or later.
Vulnerability Details
CVSS Score
2.7(low)
EPSS (30-day exploit probability)
EPSS: 0.0%
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Attack Vector
network
Attack Complexity
low
Privileges Required
high
User Interaction
none
Disclosure Date
September 2, 2026
Classification
Attack SophisticationTrivial
Taxonomy References
CWE (Weakness Type)
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81196
First tracked: September 2, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 95%