CVE-2026-81195: MasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST Route
Published Sep 2, 2026
·Updated
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.
Affected Software
1 affected component
MasterStudy LMS WordPress Plugin<3.7.46
Event History
Sep 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated attacker can request per-student enrollment and course-progress data. The affected data belongs to registered users.
2
What information may be exposed?
The vulnerable REST route can disclose a student's enrolled courses and learning progress.
3
Which installations are affected?
MasterStudy LMS WordPress Plugin versions before 3.7.46 are affected. The issue is caused by a missing authorization check on the student-courses REST route.