# MasterStudy LMS <= 3.7.52 - Authenticated (Contributor+) Missing Authorization to Payout Record Creation and Modification

- **ID:** WPSEC-2026-0497
- **Plugin:** MasterStudy LMS WordPress Plugin – for Online Courses and Education (`masterstudy-lms-learning-management-system`), https://wordpress.org/plugins/masterstudy-lms-learning-management-system/
- **Affected versions:** all versions before 3.7.53
- **Fixed in:** 3.7.53 (Update to 3.7.53 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/masterstudy-lms-learning-management-system
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0497/

## Description

The MasterStudy LMS WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 3.7.52 due to the 'stm-payout' post type inheriting default post capabilities and its meta fields lacking an authorization callback. This makes it possible for authenticated attackers, with contributor-level access and above, to create payout records and set the payee, amounts, fee amounts, status, paid flag and transaction ID of payouts they are able to edit. Attackers with author-level access and above can also publish such records, which are then included as unpaid payouts when an administrator processes pending payouts.

## References

- https://wpsec.com/vuln/WPSEC-2026-0497/
- https://plugins.svn.wordpress.org/masterstudy-lms-learning-management-system/tags/3.7.53/
- https://wordpress.org/plugins/masterstudy-lms-learning-management-system/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0497/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
