CVE-2026-81195: Unknown Masterstudy Lms WordPress Plugin

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check before returning per-student course enrollment and progress data, allowing unauthenticated attackers to disclose the enrolled courses and learning progress of any registered user.

Affected products

  • Unknown Masterstudy Lms WordPress Plugin: before 3.7.46 (fixed in 3.7.46)

Published 2026-09-02. Last modified 2026-09-03.