CVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure via student/stats REST Route
Published Sep 2, 2026
·Updated
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's learning statistics, allowing unauthenticated attackers to disclose the course counts, points, certificates, quiz and assignment totals of any registered user.
Affected Software
1 affected component
MasterStudy MasterStudy LMS WordPress Plugin<3.7.46
Event History
Sep 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated attacker can exploit it; no login or authorization is required. The exposed data concerns learning statistics for registered users.
2
What information could be disclosed?
An attacker can obtain a student's course counts, points, certificates, and quiz and assignment totals.
3
Which installations are affected?
MasterStudy LMS WordPress Plugin versions before 3.7.46 are affected. Updating to version 3.7.46 or later addresses the missing authorization check.