Executive brief
MasterStudy LMS is a learning management system plugin for WordPress used to deliver online courses and manage course sales. The plugin fails to properly check user permissions when retrieving order and sales data, allowing any logged-in student (even free accounts) to view other instructors' course sales records, order totals, and payment details by manipulating a user ID parameter. This exposes sensitive business and transaction information.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) / authorization bypass in the REST API endpoint /wp-json/lms/stm-lms/order/items. The plugin does not verify that the authenticated user has permission to access order data for the author_id parameter supplied in the request. An authenticated subscriber-level user can call this endpoint with another instructor's user ID and retrieve that instructor's complete order history, including course names, sale prices, order totals, status, and payment method. The vulnerability requires authentication and a valid WordPress REST nonce but can be exploited by any authenticated user regardless of role. This was fixed in version 3.7.46.
Affected products
- MasterStudy MasterStudy LMS before 3.7.46
Timeline
- 2026-08-31: disclosed
- 2026-09-02: patched: Fixed in version 3.7.46