← Database

CVE-2026-81194

MEDIUM CVSS: 4.3 Published: 2026-09-02 Modified: 2026-09-02

Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.

Affected Platforms

Unknown

Weakness Type

CWE-639

References