CVE-2026-81200: MasterStudy LMS < 3.7.42 - Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MasterStudy LMS WordPress pluginto a version that resolves this vulnerability.Fixed in 3.7.42
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user with the instructor role can exploit it. The issue is cross-tenant: an instructor can access billing details associated with other users' orders.
What information could be exposed?
Exposed order billing data includes the customer's name, email address, phone number, and postal address.
What does an attacker need to do?
The attacker needs an instructor-role account and must enumerate order IDs to retrieve other users' order information.
Which versions are affected?
Versions of the MasterStudy LMS WordPress Plugin before 3.7.42 are affected. Version 3.7.42 is the stated fixed-version boundary.