Junglewise Threat Intelligence

CVE-2026-81199: MasterStudy LMS information disclosure in student stats endpoint

CVE-2026-81199 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Technologies: MasterStudy LMS. Vendors: MasterStudy.

Executive brief

MasterStudy LMS is a popular WordPress learning management system plugin used to deliver online courses and track student progress. A flaw in the plugin allows unauthenticated attackers to retrieve any student's learning statistics—including course progress, points, certificates, and quiz/assignment counts—without requiring login credentials, exposing sensitive educational and performance data.

Technical details

The vulnerability is an authorization bypass (CWE-200: Exposure of Sensitive Information) in the REST API endpoint `/wp-json/masterstudy-lms/v2/student/stats/{user_id}`. The plugin fails to verify that the requester has permission to access another user's statistics before returning the data. An unauthenticated attacker can obtain a valid REST nonce (publicly exposed in page HTML) and use it to query any registered user's statistics. The attack requires network access to the WordPress site and knowledge of a valid user ID, but no authentication or user interaction. The vulnerability is fixed in version 3.7.46; all installations before this version are vulnerable.

Affected products

  • MasterStudy MasterStudy LMS before 3.7.46

Timeline

  • 2026-08-31: disclosed
  • 2026-09-02: patched: Fixed in version 3.7.46
  • 2026-09-02: advisory: CVE-2026-81199 published

References