Review
MasterStudy
CVE published 2026-08-29
CVE-2026-81200
The MasterStudy LMS WordPress Plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs. This vulnerability can be exploited by users with instructor roles to access sensitive information. To mitigate this vulner [truncated]