Executive brief
MasterStudy LMS is a WordPress plugin providing course management and curriculum functionality for online learning platforms. The plugin fails to properly verify that an instructor owns a curriculum before allowing modifications, permitting authenticated instructors to delete, modify, or inject content into courses belonging to other instructors. This can result in loss of course materials, unauthorized course tampering, and disruption of legitimate instructor workflows.
Technical details
This is an Insecure Direct Object Reference (IDOR) / broken access control vulnerability in the MasterStudy LMS WordPress plugin. The REST API endpoints for curriculum operations (PUT /wp-json/masterstudy-lms/v2/courses/{course_id}/curriculum/*, DELETE for sections and materials) perform only superficial ownership validation—checking the course_id in the URL path but not verifying that the authenticated user actually owns the target curriculum objects (sections and materials). An attacker with the instructor role can construct requests using their own course_id in the path while specifying victim curriculum object IDs (section_id, material_id) in the request body or as path parameters, bypassing the guards. This allows deletion of victim curriculum sections and materials, modification of section titles/ordering, and injection of attacker-controlled materials into victim sections. The vulnerability requires authentication (instructor role) and network access to the REST API, but no special preconditions. Fixed in version 3.7.46.
Affected products
- MasterStudy LMS before 3.7.46
Timeline
- 2026-08-31: disclosed
- 2026-09-02: patched: Fixed in version 3.7.46