PatchSiren

MasterStudy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review MasterStudy CVE published 2026-08-29

CVE-2026-81200

The MasterStudy LMS WordPress Plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs. This vulnerability can be exploited by users with instructor roles to access sensitive information. To mitigate this vulner [truncated]