Security Advisory

CVE-2026-81194

4.3
MEDIUM

Vulnerability Description

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated user including Subscribers to read other instructors' course sales records by supplying another user's identifier.
Published Date September 2, 2026
Official Source NIST NVD Advisory