CVE-2026-81339
Received Received - Intake

Unauthorized Quiz Attempt Data Exposure in MasterStudy LMS WordPress Plugin

Vulnerability report for CVE-2026-81339, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt identifier belonging to another user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
masterstudy lms_plugin to 3.7.50 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the MasterStudy LMS WordPress plugin before version 3.7.50. It allows any authenticated user with a subscriber role or higher to access quiz attempt results of other students by manipulating an attempt identifier. The plugin fails to verify ownership of the data before returning it, exposing grades, pass/fail status, and attempt timestamps.

Detection Guidance

To detect this vulnerability, check if your MasterStudy LMS WordPress plugin version is below 3.7.50. Log in as a subscriber and attempt to access quiz attempt results of other users by manipulating attempt identifiers in URLs or API calls. If data from other users is accessible, the vulnerability exists.

Impact Analysis

If you use the MasterStudy LMS plugin before version 3.7.50, an attacker with minimal access could view sensitive quiz results of other users. This includes grades, pass/fail status, and timestamps, potentially leading to privacy violations or academic dishonesty if exploited.

Compliance Impact

This vulnerability could violate data protection regulations like GDPR or HIPAA by exposing sensitive user data without proper access controls. Unauthorized access to quiz results may constitute a breach of confidentiality requirements under these standards.

Mitigation Strategies

Immediately update the MasterStudy LMS plugin to version 3.7.50 or later. If updating is not possible, restrict user roles to prevent subscribers from accessing sensitive quiz data or disable quiz functionality until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81339. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart