{"schema_version":1,"title":"MasterStudy vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in MasterStudy: 5 in the last 7 days and 16 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88847, was published on 24 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/masterstudy","json_url":"https://junglewise.ai/threats/vendors/masterstudy.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/masterstudy","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":16,"critical":0,"exploited":0,"last_7_days":5,"last_30_days":16,"last_90_days":16,"last_365_days":16},"latest":[{"cve":"CVE-2026-88847","cvss":4.3,"epss":0.0015,"slug":"cve-2026-88847-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS authorization bypass in course progress recording","severity":"medium","exploited":false,"published_at":"2026-09-24T06:17:03.533+00:00","url":"https://junglewise.ai/threats/cve-2026-88847-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-88846","cvss":5.3,"epss":0.0018,"slug":"cve-2026-88846-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS WordPress Plugin account creation bypass with registration disabled","severity":"medium","exploited":false,"published_at":"2026-09-24T06:17:03.437+00:00","url":"https://junglewise.ai/threats/cve-2026-88846-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-88845","cvss":4.3,"epss":0.0015,"slug":"cve-2026-88845-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS WordPress plugin authorization bypass in demo import","severity":"medium","exploited":false,"published_at":"2026-09-24T06:17:03.313+00:00","url":"https://junglewise.ai/threats/cve-2026-88845-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-81339","cvss":4.3,"epss":0.002,"slug":"cve-2026-81339-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS WordPress Plugin insecure direct object reference in quiz attempts","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:02.263+00:00","url":"https://junglewise.ai/threats/cve-2026-81339-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-81338","cvss":4.6,"epss":0.0009,"slug":"cve-2026-81338-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS stored HTML injection in course discussions","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:02.15+00:00","url":"https://junglewise.ai/threats/cve-2026-81338-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-88844","cvss":2.7,"epss":0.003,"slug":"cve-2026-88844-masterstudy-lms-insecure-direct-object-reference-in-course","title":"MasterStudy LMS insecure direct object reference in course enrollment data","severity":"low","exploited":false,"published_at":"2026-09-18T06:16:41.267+00:00","url":"https://junglewise.ai/threats/cve-2026-88844-masterstudy-lms-insecure-direct-object-reference-in-course"},{"cve":"CVE-2026-81340","cvss":3.8,"epss":0.0032,"slug":"cve-2026-81340-masterstudy-lms-privilege-escalation-via-rest-api-idor","title":"MasterStudy LMS privilege escalation via REST API IDOR","severity":"low","exploited":false,"published_at":"2026-09-18T06:16:39.073+00:00","url":"https://junglewise.ai/threats/cve-2026-81340-masterstudy-lms-privilege-escalation-via-rest-api-idor"},{"cve":"CVE-2026-81199","cvss":5.3,"epss":0.0047,"slug":"cve-2026-81199-masterstudy-lms-information-disclosure-in-student-stats-endpoint","title":"MasterStudy LMS information disclosure in student stats endpoint","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:19.077+00:00","url":"https://junglewise.ai/threats/cve-2026-81199-masterstudy-lms-information-disclosure-in-student-stats-endpoint"},{"cve":"CVE-2026-81198","cvss":3.8,"epss":0.0032,"slug":"cve-2026-81198-masterstudy-lms-privilege-escalation-via-idor-in-curriculum","title":"MasterStudy LMS privilege escalation via IDOR in curriculum","severity":"low","exploited":false,"published_at":"2026-09-02T06:17:18.967+00:00","url":"https://junglewise.ai/threats/cve-2026-81198-masterstudy-lms-privilege-escalation-via-idor-in-curriculum"},{"cve":"CVE-2026-81197","cvss":5.3,"epss":0.0035,"slug":"cve-2026-81197-masterstudy-lms-information-disclosure-in-rest-api","title":"MasterStudy LMS information disclosure in REST API","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:18.873+00:00","url":"https://junglewise.ai/threats/cve-2026-81197-masterstudy-lms-information-disclosure-in-rest-api"},{"cve":"CVE-2026-81196","cvss":2.7,"epss":0.003,"slug":"cve-2026-81196-masterstudy-lms-wordpress-plugin-idor-in-quiz-question-access","title":"MasterStudy LMS WordPress plugin IDOR in quiz question access","severity":"low","exploited":false,"published_at":"2026-09-02T06:17:18.777+00:00","url":"https://junglewise.ai/threats/cve-2026-81196-masterstudy-lms-wordpress-plugin-idor-in-quiz-question-access"},{"cve":"CVE-2026-81195","cvss":5.3,"epss":0.0035,"slug":"cve-2026-81195-masterstudy-lms-authorization-bypass-in-student-courses-rest-api","title":"MasterStudy LMS authorization bypass in student-courses REST API","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:18.68+00:00","url":"https://junglewise.ai/threats/cve-2026-81195-masterstudy-lms-authorization-bypass-in-student-courses-rest-api"},{"cve":"CVE-2026-81194","cvss":4.3,"epss":0.0027,"slug":"cve-2026-81194-masterstudy-lms-authorization-bypass-in-order-retrieval","title":"MasterStudy LMS authorization bypass in order retrieval","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:18.58+00:00","url":"https://junglewise.ai/threats/cve-2026-81194-masterstudy-lms-authorization-bypass-in-order-retrieval"},{"cve":"CVE-2026-81342","cvss":4.7,"epss":0.0029,"slug":"cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration","title":"MasterStudy LMS open redirect in user registration","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:58.7+00:00","url":"https://junglewise.ai/threats/cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration"},{"cve":"CVE-2026-81200","cvss":2.7,"epss":0.003,"slug":"cve-2026-81200-masterstudy-lms-insecure-direct-object-reference-in-order-access","title":"MasterStudy LMS insecure direct object reference in order access","severity":"low","exploited":false,"published_at":"2026-08-29T06:17:58.587+00:00","url":"https://junglewise.ai/threats/cve-2026-81200-masterstudy-lms-insecure-direct-object-reference-in-order-access"},{"cve":"CVE-2026-81026","cvss":4.8,"epss":0.0022,"slug":"cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler","title":"MasterStudy LMS payment verification bypass in PayPal IPN handler","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:55.99+00:00","url":"https://junglewise.ai/threats/cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler"}],"vendor":{"hub":true,"name":"MasterStudy","slug":"masterstudy","url":"https://junglewise.ai/threats/vendors/masterstudy"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":5}],"most_severe":[{"cve":"CVE-2026-81199","cvss":5.3,"epss":0.0047,"slug":"cve-2026-81199-masterstudy-lms-information-disclosure-in-student-stats-endpoint","title":"MasterStudy LMS information disclosure in student stats endpoint","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:19.077+00:00","url":"https://junglewise.ai/threats/cve-2026-81199-masterstudy-lms-information-disclosure-in-student-stats-endpoint"},{"cve":"CVE-2026-81197","cvss":5.3,"epss":0.0035,"slug":"cve-2026-81197-masterstudy-lms-information-disclosure-in-rest-api","title":"MasterStudy LMS information disclosure in REST API","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:18.873+00:00","url":"https://junglewise.ai/threats/cve-2026-81197-masterstudy-lms-information-disclosure-in-rest-api"},{"cve":"CVE-2026-81195","cvss":5.3,"epss":0.0035,"slug":"cve-2026-81195-masterstudy-lms-authorization-bypass-in-student-courses-rest-api","title":"MasterStudy LMS authorization bypass in student-courses REST API","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:18.68+00:00","url":"https://junglewise.ai/threats/cve-2026-81195-masterstudy-lms-authorization-bypass-in-student-courses-rest-api"},{"cve":"CVE-2026-88846","cvss":5.3,"epss":0.0018,"slug":"cve-2026-88846-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS WordPress Plugin account creation bypass with registration disabled","severity":"medium","exploited":false,"published_at":"2026-09-24T06:17:03.437+00:00","url":"https://junglewise.ai/threats/cve-2026-88846-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-81026","cvss":4.8,"epss":0.0022,"slug":"cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler","title":"MasterStudy LMS payment verification bypass in PayPal IPN handler","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:55.99+00:00","url":"https://junglewise.ai/threats/cve-2026-81026-masterstudy-lms-payment-verification-bypass-in-paypal-ipn-handler"},{"cve":"CVE-2026-81342","cvss":4.7,"epss":0.0029,"slug":"cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration","title":"MasterStudy LMS open redirect in user registration","severity":"medium","exploited":false,"published_at":"2026-08-29T06:17:58.7+00:00","url":"https://junglewise.ai/threats/cve-2026-81342-masterstudy-lms-open-redirect-in-user-registration"},{"cve":"CVE-2026-81338","cvss":4.6,"epss":0.0009,"slug":"cve-2026-81338-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS stored HTML injection in course discussions","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:02.15+00:00","url":"https://junglewise.ai/threats/cve-2026-81338-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-81194","cvss":4.3,"epss":0.0027,"slug":"cve-2026-81194-masterstudy-lms-authorization-bypass-in-order-retrieval","title":"MasterStudy LMS authorization bypass in order retrieval","severity":"medium","exploited":false,"published_at":"2026-09-02T06:17:18.58+00:00","url":"https://junglewise.ai/threats/cve-2026-81194-masterstudy-lms-authorization-bypass-in-order-retrieval"},{"cve":"CVE-2026-81339","cvss":4.3,"epss":0.002,"slug":"cve-2026-81339-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS WordPress Plugin insecure direct object reference in quiz attempts","severity":"medium","exploited":false,"published_at":"2026-09-23T06:17:02.263+00:00","url":"https://junglewise.ai/threats/cve-2026-81339-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"},{"cve":"CVE-2026-88847","cvss":4.3,"epss":0.0015,"slug":"cve-2026-88847-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7","title":"MasterStudy LMS authorization bypass in course progress recording","severity":"medium","exploited":false,"published_at":"2026-09-24T06:17:03.533+00:00","url":"https://junglewise.ai/threats/cve-2026-88847-the-masterstudy-lms-wordpress-plugin-wordpress-plugin-before-3-7"}],"generated_at":"2026-09-27T03:07:00.185062+00:00","technologies":[{"name":"MasterStudy LMS","slug":"masterstudy-masterstudy-lms","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/masterstudy-masterstudy-lms"}]}