CVE-2026-81026
Received Received - Intake

Unauthenticated Payment Bypass in MasterStudy LMS WordPress Plugin

Vulnerability report for CVE-2026-81026, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
masterstudy lms_wordpress_plugin to 3.7.40 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the MasterStudy LMS WordPress plugin versions before 3.7.40. It allows unauthenticated users to bypass payment by exploiting the PayPal IPN system. The plugin fails to verify payment details like amount, receiver, currency, or status before marking orders as completed, letting attackers pay a token amount for full access to paid content.

Detection Guidance

To detect this vulnerability, check if your MasterStudy LMS WordPress plugin version is below 3.7.40. You can do this by inspecting the plugin files or using WordPress admin panel. Look for unauthorized completed orders with minimal payment amounts in your payment logs.

Impact Analysis

Unauthenticated attackers can pay a minimal amount to gain access to paid content without completing the full payment. This results in lost revenue for content providers and unauthorized access to restricted materials.

Mitigation Strategies

Immediately update the MasterStudy LMS WordPress plugin to version 3.7.40 or later. Review all recent orders for suspicious activity, especially those with unusually low payment amounts. Consider temporarily disabling the PayPal IPN feature if not essential until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81026. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart