CVE-2026-88847: MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create course progress records for courses they have no access to.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with the Subscriber role. The user does not need to be enrolled in or otherwise have access to the targeted course.
What can an attacker do with this vulnerability?
An authenticated attacker can create lesson-completion and course-progress records for courses they are not enrolled in. The provided information does not indicate that the attacker can access course content or modify other users' records.
Which versions are affected?
MasterStudy LMS versions before 3.7.50 are affected. Updating to version 3.7.50 or later addresses the missing enrollment verification described.