CVE-2026-81340: The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability
infovulnerability
security
Summary
The MasterStudy LMS WordPress Plugin (a learning management system tool for WordPress) before version 3.7.50 has a security flaw where it doesn't check whether users own or have permission to modify orders through its REST API (a system that lets external programs interact with WordPress). This allows instructors to change any order on the site, including giving people free course access, removing others' paid enrollments, and editing order notes.
Solution / Mitigation
Update the MasterStudy LMS WordPress Plugin to version 3.7.50 or later.
Vulnerability Details
EPSS (30-day exploit probability)
EPSS: 0.0%
Disclosure Date
September 18, 2026
Classification
Attack SophisticationModerate
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-81340
First tracked: September 18, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 95%