CVE-2026-81200
Received
Received - Intake
MasterStudy LMS Plugin Instructor Role Order Data Exposure
Vulnerability report for CVE-2026-81200, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-29
Last updated on: 2026-08-29
Assigner: WPScan
Description
Description
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| masterstudy | lms_wordpress_plugin | to 3.7.42 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |