CVE-2026-88848: MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass
The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, allowing any member to enrol themselves into restricted paid courses outside their plan and beyond the number of courses it entitles them to.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MasterStudy LMS WordPress pluginto a version that resolves this vulnerability.Fixed in 3.7.50
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated member with Subscriber-level access or higher. They can submit an enrolment request for a course that is not covered by their membership plan.
What access could an attacker gain?
A member can enrol themselves in restricted paid courses outside their assigned plan. They can also exceed the number of courses their plan is intended to allow.
Which versions are affected?
MasterStudy LMS versions from 1.9 up to, but not including, 3.7.50 are affected.
What should be done if an immediate update is not possible?
The provided information does not identify a workaround. Review member enrolments for access to courses outside the member's plan or above its course quota, and restrict or correct unauthorized enrolments.