Masterstudy Lms Wordpress Plugin

WordPress plugin · masterstudy-lms-wordpress-plugin · WordPress.org ↗
0
Critical
0
High
11
Known total
0
Unfixed
Running Masterstudy Lms Wordpress Plugin on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 5.3
MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route
CVE.org
>=0, <3.7.46 v3.7.46 CVE-2026-81199 Sep 2, 2026
MEDIUM
CVSS 4.3
MasterStudy LMS < 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure via author_id Parameter
CVE.org
>=0, <3.7.46 v3.7.46 CVE-2026-81194 Sep 2, 2026
MEDIUM
CVSS 5.3
MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route
CVE.org
>=0, <3.7.46 v3.7.46 CVE-2026-81195 Sep 2, 2026
MEDIUM
CVSS 5.3
MasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST Route
CVE.org
>=0, <3.7.46 v3.7.46 CVE-2026-81197 Sep 2, 2026
MEDIUM
CVSS 4.8
MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN
CVE.org
>=0, <3.7.40 v3.7.40 CVE-2026-81026 Aug 29, 2026
MEDIUM
CVSS 4.7
MasterStudy LMS < 3.7.43 - Unauthenticated Open Redirect
CVE.org
>=0, <3.7.43 v3.7.43 CVE-2026-81342 Aug 29, 2026
LOW
CVSS 2.7
MasterStudy LMS 3.6.2 - < 3.7.50 - Instructor+ Student PII Disclosure via IDOR
CVE.org
>=3.6.2, <3.7.50 v3.7.50 CVE-2026-88844 Sep 18, 2026
LOW
CVSS 3.8
MasterStudy LMS < 3.7.50 - Instructor+ Order Status Manipulation via IDOR
CVE.org
>=0, <3.7.50 v3.7.50 CVE-2026-81340 Sep 18, 2026
LOW
CVSS 3.8
MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR
CVE.org
>=0, <3.7.46 v3.7.46 CVE-2026-81198 Sep 2, 2026
LOW
CVSS 2.7
MasterStudy LMS < 3.7.46 - Instructor+ Quiz Answer Disclosure via IDOR
CVE.org
>=0, <3.7.46 v3.7.46 CVE-2026-81196 Sep 2, 2026
LOW
CVSS 2.7
MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR
CVE.org
>=0, <3.7.42 v3.7.42 CVE-2026-81200 Aug 29, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.