PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-81197 MasterStudy CVE debrief

The MasterStudy LMS WordPress Plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status. This allows unauthenticated users to read the titles and IDs of unpublished (draft, pending, and private) courses. The vulnerability has a CVSS score of 5.3, indicating a medium severity level. Affected product deployments should be reviewed for exposure, and administrators should consider applying the vendor's official patch or upgrading to version 3.7.46 or later. The CVE record was published on 2026-09-02T06:17:18.873Z. Further review is needed to determine the full scope of affected products and versions.

Vendor
MasterStudy
Product
LMS WordPress Plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Administrators and users of the MasterStudy LMS WordPress Plugin, especially those with unpublished courses, should be aware of this vulnerability and take appropriate defensive actions to protect their sites and data.

Technical summary

The MasterStudy LMS WordPress Plugin before 3.7.46 has a vulnerability that allows unauthenticated users to access a REST route listing an author's courses without proper access restrictions or publication status filtering. This results in the exposure of unpublished course titles and IDs (draft, pending, and private). The vulnerability has a medium severity level with a CVSS score of 5.3. To mitigate this vulnerability, it is recommended to restrict access to the vulnerable REST route through additional authentication or authorization mechanisms, monitor for potential exploitation attempts, and perform an inventory check to identify and update vulnerable instances of the MasterStudy LMS WordPress Plugin. Implementing compensating controls, such as web application firewalls, may also help detect and prevent exploitation.

Defensive priority

Medium-priority defensive actions are recommended due to the MEDIUM CVSS score of 5.3 for CVE-2026-81197, which allows unauthenticated users to access unpublished course information.

Recommended defensive actions

  • Review and apply the vendor's official patch or upgrade to version 3.7.46 or later.
  • Restrict access to the vulnerable REST route through additional authentication or authorization mechanisms.
  • Monitor for and respond to potential exploitation attempts targeting this vulnerability.
  • Perform an inventory check to identify and update vulnerable instances of the MasterStudy LMS WordPress Plugin.
  • Consider implementing compensating controls, such as web application firewalls, to detect and prevent exploitation.

Evidence notes

Evidence from the NVD and WPScan indicates that the MasterStudy LMS WordPress Plugin before 3.7.46 has a vulnerability allowing unauthenticated users to read unpublished course titles and IDs. Further review is needed to determine the full scope of affected products and versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-81197 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-81197

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-81197 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81197

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.