PatchSiren cyber security CVE debrief
CVE-2026-81194 MasterStudy CVE debrief
The MasterStudy LMS WordPress Plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier. This vulnerability affects users of the MasterStudy LMS WordPress Plugin, particularly those with sensitive course sales records. The issue arises from inadequate authorization checks, potentially exposing sensitive course sales data to unauthorized users. Defenders should focus on verifying user roles, restricting access to sensitive data, and updating the plugin to version 3.7.46 or later. Additionally, users should review their security configurations and monitor for unauthorized access to course sales records. Evidence is limited to CVE and NVD entries. Further investigation is needed to determine the full scope of the issue.
- Vendor
- MasterStudy
- Product
- MasterStudy LMS WordPress Plugin
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Users of the MasterStudy LMS WordPress Plugin, particularly those with sensitive course sales records, should be aware of this vulnerability and take steps to protect themselves. This includes verifying user roles, restricting access to sensitive data, and updating the plugin to version 3.7.46 or later. Additionally, users should review their security configurations and monitor for unauthorized access to course sales records.
Technical summary
The MasterStudy LMS WordPress Plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier. This vulnerability affects users of the MasterStudy LMS WordPress Plugin, particularly those with sensitive course sales records. The issue arises from inadequate authorization checks, potentially exposing sensitive course sales data to unauthorized users. Defenders should focus on verifying user roles, restricting access to sensitive data, and updating the plugin to version 3.7.46 or later.
Defensive priority
Authenticated users may access unauthorized course sales records. Verify user roles and restrict access to sensitive data.
Recommended defensive actions
- Verify user roles and restrict access to sensitive data
- Update MasterStudy LMS WordPress Plugin to version 3.7.46 or later
- Monitor for unauthorized access to course sales records
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue. Evidence is limited to CVE and NVD entries. Defenders should verify affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations. The MasterStudy LMS WordPress Plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier. Additional review of product documentation and security configurations may be necessary to fully understand the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81194 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81194
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81194 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81194
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/727903d4-ce0f-4ab4-bbd4-c973091e0b8f/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.