MasterStudy LMS <= 3.7.52 - Authenticated (Contributor+) Missing Authorization to Payout Record Creation and Modification
- ID
- WPSEC-2026-0497
- Plugin
- MasterStudy LMS WordPress Plugin – for Online Courses and Education (masterstudy-lms-learning-management-system)
- Affected
- all versions before 3.7.53
- Remediation
- Update to 3.7.53 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- MasterStudy LMS on WPSec AttackSurface
- Fix released
- Published
Description
The MasterStudy LMS WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 3.7.52 due to the 'stm-payout' post type inheriting default post capabilities and its meta fields lacking an authorization callback. This makes it possible for authenticated attackers, with contributor-level access and above, to create payout records and set the payee, amounts, fee amounts, status, paid flag and transaction ID of payouts they are able to edit. Attackers with author-level access and above can also publish such records, which are then included as unpaid payouts when an administrator processes pending payouts.
References
- https://wpsec.com/vuln/WPSEC-2026-0497/
- https://plugins.svn.wordpress.org/masterstudy-lms-learning-management-system/tags/3.7.53/
- https://wordpress.org/plugins/masterstudy-lms-learning-management-system/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS