Vulnerabilities / MasterStudy LMS / WPSEC-2026-0497

MasterStudy LMS <= 3.7.52 - Authenticated (Contributor+) Missing Authorization to Payout Record Creation and Modification

Medium 4.3 CWE-862Fixed in 3.7.53
ID
WPSEC-2026-0497
Plugin
MasterStudy LMS WordPress Plugin – for Online Courses and Education (masterstudy-lms-learning-management-system)
Affected
all versions before 3.7.53
Remediation
Update to 3.7.53 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
MasterStudy LMS on WPSec AttackSurface
Fix released
Published

Description

The MasterStudy LMS WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 3.7.52 due to the 'stm-payout' post type inheriting default post capabilities and its meta fields lacking an authorization callback. This makes it possible for authenticated attackers, with contributor-level access and above, to create payout records and set the payee, amounts, fee amounts, status, paid flag and transaction ID of payouts they are able to edit. Attackers with author-level access and above can also publish such records, which are then included as unpaid payouts when an administrator processes pending payouts.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0