Executive brief
MasterStudy LMS is a WordPress plugin used to create and manage online courses and learning platforms. A security flaw in versions up to 3.7.30 allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to do. This could allow students or low-level users to interfere with site settings or content, potentially disrupting the learning environment.
Technical details
A broken access control vulnerability exists in the MasterStudy LMS plugin for WordPress due to missing authorization checks (CWE-862). An attacker with Subscriber-level privileges can exploit this flaw via network requests to execute functions or modify data that should be restricted to higher-privileged roles. The vulnerability is present in versions up to and including 3.7.30. A fix is available in version 3.7.31, which implements the necessary access control checks.
Affected products
- StylemixThemes MasterStudy LMS <= 3.7.30
Timeline
- 2026-02-17: other: Reported by researcher 'lagi bljr'
- 2026-06-26: disclosed: Early warning sent to Patchstack customers
- 2026-06-26: patched: Version 3.7.31 released to address the issue
- 2026-06-26: advisory: Public advisory published by Patchstack and NVD