CVE-2026-81196
Received Received - Intake

MasterStudy LMS Plugin Quiz Question Access Control Flaw

Vulnerability report for CVE-2026-81196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers, allowing users with instructor access to read other instructors' quiz questions, including the correct answers and explanations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
masterstudy lms to 3.7.46 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the MasterStudy LMS WordPress plugin before version 3.7.46. It allows users with instructor access to read quiz questions, correct answers, and explanations belonging to other instructors due to improper verification of quiz question identifier ownership.

Detection Guidance

Check if your WordPress site uses the MasterStudy LMS plugin version prior to 3.7.46. Log in as an instructor and attempt to access quiz questions belonging to other instructors to verify if unauthorized access is possible.

Impact Analysis

If you are an instructor using the MasterStudy LMS plugin before version 3.7.46, another instructor could access your quiz questions, answers, and explanations. This could lead to unauthorized exposure of sensitive educational content and potential misuse of quiz materials.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by exposing sensitive quiz content, including correct answers and explanations, to unauthorized instructors. Unauthorized access to such data may violate confidentiality requirements under these regulations.

Mitigation Strategies

Update the MasterStudy LMS plugin to version 3.7.46 or later immediately. Remove instructor-level access for users who do not require it to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart