CVE-2026-81200
Received Received - Intake

MasterStudy LMS Plugin Instructor Role Order Data Exposure

Vulnerability report for CVE-2026-81200, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
masterstudy lms_wordpress_plugin to 3.7.42 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the MasterStudy LMS WordPress plugin versions before 3.7.42. It allows users with the instructor role to access and disclose other users' order billing details, including names, email addresses, phone numbers, and postal addresses, by enumerating order IDs.

Detection Guidance

To detect this vulnerability, check if users with the instructor role can access order details of other users by enumerating order IDs. Use WordPress admin access to verify if billing information is exposed when accessing order endpoints with different IDs.

Impact Analysis

If you are a user with the instructor role on a site using the vulnerable plugin, you could access sensitive billing information of other users. If you are an administrator, your users' personal and financial data could be exposed, leading to privacy violations and potential misuse of data.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personal and sensitive data. GDPR requires protection of personal data, and HIPAA mandates safeguarding protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Immediately update the MasterStudy LMS WordPress plugin to version 3.7.42 or later. Review user roles and permissions to ensure instructors cannot access sensitive order information. Monitor for unauthorized access attempts to order data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81200. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart