PatchSiren cyber security CVE debrief
CVE-2026-81197 MasterStudy CVE debrief
The MasterStudy LMS WordPress Plugin before 3.7.46 does not restrict access to a REST route that lists an author's courses, nor does it filter that listing by publication status. This allows unauthenticated users to read the titles and IDs of unpublished (draft, pending, and private) courses. The vulnerability has a CVSS score of 5.3, indicating a medium severity level. Affected product deployments should be reviewed for exposure, and administrators should consider applying the vendor's official patch or upgrading to version 3.7.46 or later. The CVE record was published on 2026-09-02T06:17:18.873Z. Further review is needed to determine the full scope of affected products and versions.
- Vendor
- MasterStudy
- Product
- LMS WordPress Plugin
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Administrators and users of the MasterStudy LMS WordPress Plugin, especially those with unpublished courses, should be aware of this vulnerability and take appropriate defensive actions to protect their sites and data.
Technical summary
The MasterStudy LMS WordPress Plugin before 3.7.46 has a vulnerability that allows unauthenticated users to access a REST route listing an author's courses without proper access restrictions or publication status filtering. This results in the exposure of unpublished course titles and IDs (draft, pending, and private). The vulnerability has a medium severity level with a CVSS score of 5.3. To mitigate this vulnerability, it is recommended to restrict access to the vulnerable REST route through additional authentication or authorization mechanisms, monitor for potential exploitation attempts, and perform an inventory check to identify and update vulnerable instances of the MasterStudy LMS WordPress Plugin. Implementing compensating controls, such as web application firewalls, may also help detect and prevent exploitation.
Defensive priority
Medium-priority defensive actions are recommended due to the MEDIUM CVSS score of 5.3 for CVE-2026-81197, which allows unauthenticated users to access unpublished course information.
Recommended defensive actions
- Review and apply the vendor's official patch or upgrade to version 3.7.46 or later.
- Restrict access to the vulnerable REST route through additional authentication or authorization mechanisms.
- Monitor for and respond to potential exploitation attempts targeting this vulnerability.
- Perform an inventory check to identify and update vulnerable instances of the MasterStudy LMS WordPress Plugin.
- Consider implementing compensating controls, such as web application firewalls, to detect and prevent exploitation.
Evidence notes
Evidence from the NVD and WPScan indicates that the MasterStudy LMS WordPress Plugin before 3.7.46 has a vulnerability allowing unauthenticated users to read unpublished course titles and IDs. Further review is needed to determine the full scope of affected products and versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-81197 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-81197
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-81197 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-81197
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/8738320c-eb44-46b9-b809-b5cb786cb3e4/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.