---
id: CVE-2026-81340
title: >-
  The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not
  perform per-object ownership or capability checks when updating orders through
  its REST API, allowing users with the Instructor role to modify any order on
  the…
summary: >-
  The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not
  perform per-object ownership or capability checks when updating orders through
  its REST API, allowing users with the Instructor role to modify any order on
  the…
severity: low
cvss: 3.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-639
product: MasterStudy LMS WordPress Plugin
affected:
  - masterstudy_lms_wordpress_plugin < 3.7.50
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81340'
references:
  - url: 'https://wpscan.com/vulnerability/8006876f-27bb-483d-b4e4-9fa4414d16f0/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00318
epssPercentile: 0.2223
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T11:09:19.265982Z'
ingestedAt: '2026-09-18T06:36:37.979Z'
---

## Overview

The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the site, granting free course enrolment, revoking other users' paid enrolments, and tampering with order notes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
