{
 "id": "WPSEC-2026-0497",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0497/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0497/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0497/index.md",
 "title": "MasterStudy LMS <= 3.7.52 - Authenticated (Contributor+) Missing Authorization to Payout Record Creation and Modification",
 "description": "The MasterStudy LMS WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 3.7.52 due to the 'stm-payout' post type inheriting default post capabilities and its meta fields lacking an authorization callback. This makes it possible for authenticated attackers, with contributor-level access and above, to create payout records and set the payee, amounts, fee amounts, status, paid flag and transaction ID of payouts they are able to edit. Attackers with author-level access and above can also publish such records, which are then included as unpaid payouts when an administrator processes pending payouts.",
 "plugin": {
  "slug": "masterstudy-lms-learning-management-system",
  "name": "MasterStudy LMS",
  "full_name": "MasterStudy LMS WordPress Plugin – for Online Courses and Education",
  "wordpress_org": "https://wordpress.org/plugins/masterstudy-lms-learning-management-system/",
  "advisories_url": "https://wpsec.com/vuln/plugin/masterstudy-lms-learning-management-system/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/masterstudy-lms-learning-management-system"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.7.53",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.7.53"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.7.53",
 "remediation": "Update to 3.7.53 or later.",
 "fix_released": "2026-10-06T09:58:43+00:00",
 "published": "2026-10-07T10:52:45+00:00",
 "updated": "2026-10-06T19:05:37.271173+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0497/",
  "https://plugins.svn.wordpress.org/masterstudy-lms-learning-management-system/tags/3.7.53/",
  "https://wordpress.org/plugins/masterstudy-lms-learning-management-system/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/masterstudy-lms-learning-management-system",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}