Executive brief
MasterStudy LMS is a popular WordPress plugin used to create and manage online courses and learning platforms. A security flaw in the plugin allows unauthorized individuals to manipulate user-related data or states without needing to log in. This could potentially allow attackers to interfere with student progress or modify user settings, though it does not directly lead to full site takeover or data theft.
Technical details
The MasterStudy LMS plugin for WordPress (versions up to 3.7.39) contains a broken access control vulnerability classified as CWE-345 (Insufficient Verification of Data Authenticity). The flaw exists because the application fails to properly validate the source or integrity of data in certain functions, allowing an unauthenticated remote attacker to manipulate user states. This typically involves missing nonce checks or insufficient authorization logic. An attacker can exploit this over the network without user interaction to modify specific user-related parameters. The issue is resolved in version 3.7.40.
Affected products
- StylemixThemes MasterStudy LMS n/a through 3.7.39
Timeline
- 2026-07-17: other: Reported by Abdullah Kareem
- 2026-07-31: advisory: Published by Patchstack and NVD
- 2026-07-31: patched: Fixed in version 3.7.40