Executive brief
MasterStudy LMS is a popular WordPress learning management system plugin used to deliver online courses and track student progress. A flaw in the plugin allows unauthenticated attackers to retrieve any student's learning statistics—including course progress, points, certificates, and quiz/assignment counts—without requiring login credentials, exposing sensitive educational and performance data.
Technical details
The vulnerability is an authorization bypass (CWE-200: Exposure of Sensitive Information) in the REST API endpoint `/wp-json/masterstudy-lms/v2/student/stats/{user_id}`. The plugin fails to verify that the requester has permission to access another user's statistics before returning the data. An unauthenticated attacker can obtain a valid REST nonce (publicly exposed in page HTML) and use it to query any registered user's statistics. The attack requires network access to the WordPress site and knowledge of a valid user ID, but no authentication or user interaction. The vulnerability is fixed in version 3.7.46; all installations before this version are vulnerable.
Affected products
- MasterStudy MasterStudy LMS before 3.7.46
Timeline
- 2026-08-31: disclosed
- 2026-09-02: patched: Fixed in version 3.7.46
- 2026-09-02: advisory: CVE-2026-81199 published