MasterStudy LMS WordPress Plugin – for Online Courses and Education, CVE-2026-88844
- CVE, Research URL
- Home page URL
-
Security reports for MasterStudy LMS WordPress Plugin – for Online Courses and Education
- Published on
- Sep 18, 2026
- Research Description
- The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50's Instructor role to disclose the names and email addresses of students enrolled in other instructors' courses.
- Affected versions
-
Min 3.6.2, max 3.7.50.
- Status
-
vulnerable