CVE-2026-81198: MasterStudy LMS < 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and Tampering via IDOR
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with the instructor role can exploit it. The issue affects actions on curriculum sections and materials for courses owned by other instructors.
Is a default or unauthenticated WordPress installation exposed?
The available information indicates that authentication and the instructor role are required. It does not indicate that unauthenticated users can exploit the issue.
What versions are affected?
MasterStudy LMS versions before 3.7.46 are affected. Updating to version 3.7.46 or later addresses the affected version range.
What should be prioritized if an update cannot be applied immediately?
Restrict instructor-role access to trusted users, since instructors are the role identified as able to exploit the issue. Review curriculum sections and materials across courses for unauthorized deletion or modification.