CVE-2026-73404: WordPress MasterStudy LMS plugin <= 3.7.41 - Broken Access Control vulnerability
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MasterStudy LMS pluginto a version that resolves this vulnerability.Fixed in 3.7.42
Event History
Frequently Asked Questions
Which deployments are most relevant to this issue?
The affected software is the WordPress MasterStudy LMS plugin through version 3.7.41. The issue is described as subscriber broken access control, indicating that sites where users can hold the Subscriber role are relevant to triage.
What level of access does an attacker need to exploit it?
The vector is network-accessible, exploitation complexity is low, and no user interaction is required. An attacker needs low-level privileges, reflected by the required-privileges metric and the subscriber-specific description.
What is the expected security impact?
The provided impact metrics indicate high confidentiality impact, with no integrity or availability impact. This suggests the primary concern is unauthorized access to information rather than modification or disruption.