CVE-2026-81198

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum object before acting on it, allowing authenticated users with the instructor role to delete or modify curriculum sections and materials belonging to courses owned by other instructors.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 06:17

Updated : 2026-09-03 17:50


NVD link : CVE-2026-81198

Mitre link : CVE-2026-81198

CVE.ORG link : CVE-2026-81198


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key