CVE-2026-88847
Received Received - Intake

Unauthorized Course Progress Update in MasterStudy LMS WordPress Plugin

Vulnerability report for CVE-2026-88847, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: WPScan

Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
masterstudy lms to 3.7.50 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the MasterStudy LMS WordPress plugin before version 3.7.50. It allows any authenticated user, including subscribers, to create lesson completion records for courses they are not enrolled in or have no access to. The plugin fails to verify user enrollment before recording progress.

Detection Guidance

To detect this vulnerability, check if your MasterStudy LMS plugin version is below 3.7.50. You can do this by logging into your WordPress admin panel, navigating to the Plugins section, and looking for the MasterStudy LMS plugin version. If it is outdated, update it immediately.

Impact Analysis

An attacker could manipulate course progress records, potentially gaining unauthorized access to course materials or falsifying completion status. This could affect course integrity and user credentials.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized users to manipulate course progress records. For GDPR, this may affect data integrity and user consent if progress data is used for certifications or compliance tracking. For HIPAA, if the LMS handles protected health information, unauthorized access or falsified records could violate confidentiality and audit requirements.

Mitigation Strategies

Immediately update the MasterStudy LMS plugin to version 3.7.50 or later. This version addresses the vulnerability by verifying user enrollment before recording lesson progress. Failure to update may allow unauthorized users to manipulate course records.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88847. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart