Unknown MasterStudy LMS WordPress Plugin

17 known vulnerabilities in Unknown MasterStudy LMS WordPress Plugin, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-88847 CVSS 4.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording…
  • CVE-2026-88846 CVSS 5.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before…
  • CVE-2026-88845 CVSS 4.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative…
  • CVE-2026-88843 CVSS 7.2 high The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to…
  • CVE-2026-81339 CVSS 4.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz…
  • CVE-2026-81338 CVSS 4.6 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content…
  • CVE-2026-88844 CVSS 2.7 low The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before…
  • CVE-2026-81340 CVSS 3.8 low The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when…
  • CVE-2026-81199 CVSS 5.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning a student's…
  • CVE-2026-81198 CVSS 3.8 low The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before…
  • CVE-2026-81197 CVSS 5.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route that lists an author's…
  • CVE-2026-81196 CVSS 2.7 low The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question identifiers…
  • CVE-2026-81195 CVSS 5.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student…
  • CVE-2026-81194 CVSS 4.3 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item…
  • CVE-2026-81342 CVSS 4.7 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user…
  • CVE-2026-81200 CVSS 2.7 low The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any…
  • CVE-2026-81026 CVSS 4.8 medium The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment…