PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81194 MasterStudy CVE debrief

The MasterStudy LMS WordPress Plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier. This vulnerability affects users of the MasterStudy LMS WordPress Plugin, particularly those with sensitive course sales records. The issue arises from inadequate authorization checks, potentially exposing sensitive course sales data to unauthorized users. Defenders should focus on verifying user roles, restricting access to sensitive data, and updating the plugin to version 3.7.46 or later. Additionally, users should review their security configurations and monitor for unauthorized access to course sales records. Evidence is limited to CVE and NVD entries. Further investigation is needed to determine the full scope of the issue.

Vendor
MasterStudy
Product
MasterStudy LMS WordPress Plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Users of the MasterStudy LMS WordPress Plugin, particularly those with sensitive course sales records, should be aware of this vulnerability and take steps to protect themselves. This includes verifying user roles, restricting access to sensitive data, and updating the plugin to version 3.7.46 or later. Additionally, users should review their security configurations and monitor for unauthorized access to course sales records.

Technical summary

The MasterStudy LMS WordPress Plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier. This vulnerability affects users of the MasterStudy LMS WordPress Plugin, particularly those with sensitive course sales records. The issue arises from inadequate authorization checks, potentially exposing sensitive course sales data to unauthorized users. Defenders should focus on verifying user roles, restricting access to sensitive data, and updating the plugin to version 3.7.46 or later.

Defensive priority

Authenticated users may access unauthorized course sales records. Verify user roles and restrict access to sensitive data.

Recommended defensive actions

  • Verify user roles and restrict access to sensitive data
  • Update MasterStudy LMS WordPress Plugin to version 3.7.46 or later
  • Monitor for unauthorized access to course sales records
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further investigation is needed to determine the full scope of the issue. Evidence is limited to CVE and NVD entries. Defenders should verify affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations. The MasterStudy LMS WordPress Plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier. Additional review of product documentation and security configurations may be necessary to fully understand the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81194 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81194

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81194 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81194

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.