MasterStudy LMS WordPress Plugin – for Online Courses and Education, CVE-2026-81026
- CVE, Research URL
- Home page URL
-
Security reports for MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Published on
- Aug 29, 2026
- Research Description
- The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access to paid content by paying only a token amount.
- Affected versions
-
max 3.7.40.
- Status
-
vulnerable